Threat Intelligence / Actor / APT38
APT38
As of 2026-08-25, APT38 is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 41 threats spanning supply chain, vulnerability, malware. Also known as Sapphire Sleet, APT38 - G0082, beagleboyz, bluenoroff.
Also known as: APT38, Sapphire Sleet, APT38 - G0082, beagleboyz, bluenoroff, copernicium, g0082, nickel gladstone, stardust chollima, UNC1069, UNC1069 (BlueNoroff), alluring pisces
Tracked threats
- Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor — CRITICAL
- Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet) — CRITICAL
- Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack — CRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971) — CRITICAL
- Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026) — CRITICAL
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages — HIGH
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel") — HIGH
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE Backdoors — CRITICAL
- Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and Typo-Crypto npm Packages in Supply-Chain Campaign — CRITICAL
- Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled — HIGH
- BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls — HIGH
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering — HIGH
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain Theft — HIGH
- NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY — MEDIUM
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise — MEDIUM
- PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret) — HIGH
- ClickFix Social-Engineering Technique Becomes Dominant Malware Delivery and Defense-Evasion Vector (CrashFix, FileFix, ConsentFix Variants) — HIGH
- Lazarus-Linked npm Malware Masquerades as Rollup Polyfills (rollup-packages-polyfill-core, rollup-runtime-polyfill-core, swift-parse-stream, quirky-token, rollup-plugin-polyfill-connect, react-icon-svgs) — HIGH
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion Techniques — HIGH
- Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked Maintainer Account — CRITICAL
- Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages Compromised — CRITICAL
- Mastra npm Supply-Chain Compromise (@mastra/* namespace) via Typosquatted 'easy-day-js' — Multi-Stage Cross-Platform Infostealer — CRITICAL
- Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558) — HIGH
- RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain — HIGH
- Lazarus RemotePE Memory-Only RAT — DPAPILoader + RemotePELoader Chain Targeting Financial & Cryptocurrency Firms — HIGH
- Lazarus Group (DPRK) Hides BeaverTail / InvisibleFerret Loader in Git Hooks via precommit.vercel.app — Contagious Interview / TaskJacker Evolution (May 2026) — HIGH
- KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026) — CRITICAL
- Sapphire Sleet (DPRK/BlueNoroff) macOS Intrusion Campaign Targeting Cryptocurrency, Web3, and Venture Capital Sectors — HIGH
- Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple Certificate Rotation — DPRK UNC1069 / Sapphire Sleet WAVESHAPER.V2 — CRITICAL
- DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning — HIGH
- Axios npm Supply Chain Compromise — WAVESHAPER.V2 Cross-Platform RAT Deployment by UNC1069/Sapphire Sleet (DPRK) — CRITICAL
- Axios npm Supply Chain Compromise by Sapphire Sleet (DPRK) — Cross-Platform RAT via Phantom Dependency — CRITICAL
- UNC1069 Compromises Axios NPM Package in Supply Chain Attack Deploying WAVESHAPER.V2 Cross-Platform Backdoor — CRITICAL
- North Korea (UNC1069) Supply Chain Compromise of Axios NPM Package via Backdoored plain-crypto-js Dependency — CRITICAL
- Supply Chain Attacks on Crypto Ecosystem via Developer Toolchain Compromise — HIGH
- UNC4899/Jade Sleet Cryptocurrency Exchange Breach via AirDrop Trojanization and Cloud Infrastructure Compromise — CRITICAL
- Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. Healthcare — CRITICAL
- Contagious Interview IDE Task Hijacking — North Korean BeaverTail/PyLangGhost/GolangGhost via VS Code & Cursor Tasks, GitHub Gist Staging, Developer Targeting — HIGH
- Lazarus Group Medusa Ransomware — North Korean State-Backed Extortion Targeting US Healthcare and Middle East — CRITICAL
- Matryoshka ClickFix macOS Variant — Nested Heredoc Obfuscation, AppleScript Credential Stealer, Trezor Suite Replacement, Ledger Live Surgical Patching, API-Gated C2 — HIGH
- LABYRINTH CHOLLIMA Evolves into Three DPRK Adversaries — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →