Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-03

UNC1069

Also known as:Sapphire SleetAPT38APT38 - G0082CryptoCoreMASANStardust ChollimaCageyChameleonBlueNoroff-adjacentNICKEL GLADSTONEBeagleBoyzBluenoroffCOPERNICIUM

As of 2026-10-07, UNC1069 is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 18 threats spanning supply chain. Also known as Sapphire Sleet, APT38, APT38 - G0082, CryptoCore. ATT&CK coverage spans 108 techniques across 14 tactics in 18 of 18 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1105 (Ingress Tool Transfer).

Tracked threats
1814 critical · 4 high
First seen
2026-03-30
Last seen
2026-10-07
ATT&CK techniques
108across 18 of 18 threats
Related CVEs
0None referenced
Attribution
North KoreaNation or origin
Nation: North Korea · 18 tracked threat(s) · Categories: SUPPLY_CHAIN

Activity timeline

UNC1069 appears in 18 tracked threats between and ; the busiest month was 2026-04 with 5 reports.

ATT&CK techniques observed

108 techniques observed across 18 of 18 tracked threats · Stealth (formerly Defense Evasion) (22), Command and Control (15), Resource Development (14), Execution (11), Initial Access (9), Discovery (8)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 17 of 18 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 13 of 18 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 11 of 18 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 11 of 18 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 9 of 18 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 9 of 18 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 9 of 18 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 9 of 18 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 9 of 18 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 9 of 18 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 9 of 18 tracked threats
  • T1059.001 PowerShell — Executionobserved in 8 of 18 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 8 of 18 tracked threats
  • T1195.001 Compromise Software Dependencies and Development Tools — Initial Accessobserved in 8 of 18 tracked threats
  • T1571 Non-Standard Port — Command and Controlobserved in 8 of 18 tracked threats

Tracked threats