Threat Intelligence / Actor / APT38

APT38

As of 2026-08-25, APT38 is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 41 threats spanning supply chain, vulnerability, malware. Also known as Sapphire Sleet, APT38 - G0082, beagleboyz, bluenoroff.

Nation: North Korea (DPRK) · 41 tracked threat(s) · Categories: SUPPLY_CHAIN, VULNERABILITY, MALWARE, APT, THREAT_INTEL, CAMPAIGN, PHISHING, RANSOMWARE

Also known as: APT38, Sapphire Sleet, APT38 - G0082, beagleboyz, bluenoroff, copernicium, g0082, nickel gladstone, stardust chollima, UNC1069, UNC1069 (BlueNoroff), alluring pisces

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence