Threat Intelligence / Actor / Sapphire Sleet (BlueNoroff

Sapphire Sleet (BlueNoroff

As of 2026-08-25, Sapphire Sleet (BlueNoroff is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 16 threats spanning supply chain. Also known as UNC1069), Sapphire Sleet, alluring pisces, bluenoroff.

Nation: North Korea · 16 tracked threat(s) · Categories: SUPPLY_CHAIN

Also known as: Sapphire Sleet (BlueNoroff, UNC1069, UNC1069), Sapphire Sleet, alluring pisces, bluenoroff, cageychameleon, copernicium, cryptocore, genie spider, stardust chollima, APT38

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence