Threadlinqs IntelligenceStart free

Threat actorNorth Korea (DPRK)Tracked since 2026-02

Jade Sleet

As of 2026-09-28, Jade Sleet is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning supply chain, apt, malware. ATT&CK coverage spans 77 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1071.001 (Web Protocols), T1195.002 (Compromise Software Supply Chain).

Tracked threats
63 critical · 3 high
First seen
2026-02-27
Last seen
2026-09-26
ATT&CK techniques
77across 6 of 6 threats
Related CVEs
1Referenced by its activity
Attribution
North Korea (DPRK)Nation or origin
Nation: North Korea (DPRK) · 6 tracked threat(s) · Categories: SUPPLY_CHAIN, APT, MALWARE, VULNERABILITY

Activity timeline

Jade Sleet appears in 6 tracked threats between and ; the busiest month was 2026-09 with 3 reports.

ATT&CK techniques observed

77 techniques observed across 6 of 6 tracked threats · Stealth (formerly Defense Evasion) (11), Execution (9), Command and Control (8), Initial Access (7), Resource Development (7), Discovery (6)
  • T1078 Valid Accounts — Initial Accessobserved in 4 of 6 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 6 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 3 of 6 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 6 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 6 tracked threats
  • T1059.007 JavaScript — Executionobserved in 2 of 6 tracked threats
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 2 of 6 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 6 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 6 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 2 of 6 tracked threats
  • T1195.001 Compromise Software Dependencies and Development Tools — Initial Accessobserved in 2 of 6 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 2 of 6 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Jade Sleet activity