Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-02

APT38

Also known as:Alluring PiscesSapphire SleetAPT38 - G0082STARDUST CHOLLIMATeamPCPALTERED SPIDERUNC1069BlueNoroffUNC6508Volt Typhoon - G1017Volt TyphoonPinstripe Lightning

As of 2026-10-08, APT38 is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 48 threats spanning supply chain, apt, zero day. Also known as Alluring Pisces, Sapphire Sleet, APT38 - G0082, STARDUST CHOLLIMA. ATT&CK coverage spans 249 techniques across 16 tactics in 48 of 48 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1041 (Exfiltration Over C2 Channel).

Tracked threats
4823 critical · 23 high · 2 medium
First seen
2026-02-12
Last seen
2026-10-07
ATT&CK techniques
249across 48 of 48 threats
Related CVEs
69Referenced by its activity
Attribution
North KoreaNation or origin
Nation: North Korea · 48 tracked threat(s) · Categories: SUPPLY_CHAIN, APT, ZERO_DAY, VULNERABILITY, MALWARE, THREAT_INTEL, CAMPAIGN, PHISHING, RANSOMWARE

Activity timeline

APT38 appears in 48 tracked threats between and ; the busiest month was 2026-07 with 13 reports.

ATT&CK techniques observed

249 techniques observed across 48 of 48 tracked threats · Stealth (formerly Defense Evasion) (49), Persistence (23), Resource Development (23), Command and Control (22), Discovery (21), Credential Access (20)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 36 of 48 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 34 of 48 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 32 of 48 tracked threats
  • T1005 Data from Local System — Collectionobserved in 30 of 48 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 29 of 48 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 26 of 48 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 24 of 48 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 21 of 48 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 20 of 48 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 20 of 48 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 20 of 48 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 20 of 48 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 18 of 48 tracked threats
  • T1059.001 PowerShell — Executionobserved in 18 of 48 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 18 of 48 tracked threats

Tracked threats

Related CVEs

40 of 69 CVEs referenced by tracked APT38 activity