Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-03

Sapphire Sleet

Also known as:UNC1069APT38Stardust ChollimaAPT38 - G0082

As of 2026-09-30, Sapphire Sleet is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 36 threats spanning supply chain, apt, zero day. Also known as UNC1069, APT38, Stardust Chollima, APT38 - G0082. ATT&CK coverage spans 214 techniques across 16 tactics in 36 of 36 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel).

Tracked threats
3619 critical · 15 high · 2 medium
First seen
2026-03-30
Last seen
2026-09-26
ATT&CK techniques
214across 36 of 36 threats
Related CVEs
60Referenced by its activity
Attribution
North KoreaNation or origin
Nation: North Korea · 36 tracked threat(s) · Categories: SUPPLY_CHAIN, APT, ZERO_DAY, VULNERABILITY, MALWARE, THREAT_INTEL, CAMPAIGN, PHISHING

Activity timeline

Sapphire Sleet appears in 36 tracked threats between and ; the busiest month was 2026-07 with 13 reports.

ATT&CK techniques observed

214 techniques observed across 36 of 36 tracked threats · Stealth (formerly Defense Evasion) (46), Resource Development (23), Command and Control (22), Persistence (18), Credential Access (17), Discovery (17)
  • T1082 System Information Discovery — Discoveryobserved in 29 of 36 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 28 of 36 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 21 of 36 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 21 of 36 tracked threats
  • T1005 Data from Local System — Collectionobserved in 19 of 36 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 19 of 36 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 18 of 36 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 18 of 36 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 17 of 36 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 16 of 36 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 15 of 36 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 15 of 36 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 14 of 36 tracked threats
  • T1059.001 PowerShell — Executionobserved in 14 of 36 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 14 of 36 tracked threats

Tracked threats

Related CVEs

40 of 60 CVEs referenced by tracked Sapphire Sleet activity