# UNC1069

> As of 2026-10-07, UNC1069 is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 18 threats spanning supply chain. Also known as Sapphire Sleet, APT38, APT38 - G0082, CryptoCore. ATT&CK coverage spans 108 techniques across 14 tactics in 18 of 18 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1082 (System Information Discovery), T1105 (Ingress Tool Transfer).

- **Nation:** North Korea
- **Tracked threats:** 18
- **Categories:** SUPPLY_CHAIN
- **Also known as:** Sapphire Sleet, APT38, APT38 - G0082, CryptoCore, MASAN, Stardust Chollima, CageyChameleon, BlueNoroff-adjacent, NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, COPERNICIUM
- **As of:** 2026-10-07

## ATT&CK techniques observed

108 techniques observed across 18 of 18 tracked threats. Tactics: Stealth (formerly Defense Evasion) (22), Command and Control (15), Resource Development (14), Execution (11), Initial Access (9), Discovery (8).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 17 of 18 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 13 of 18 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 11 of 18 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 11 of 18 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 9 of 18 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 9 of 18 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 9 of 18 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 9 of 18 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 9 of 18 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 9 of 18 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 9 of 18 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 8 of 18 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 8 of 18 tracked threats
- [T1195.001](https://intel.threadlinqs.com/technique/T1195.001) Compromise Software Dependencies and Development Tools — Initial Access — observed in 8 of 18 tracked threats
- [T1571](https://intel.threadlinqs.com/technique/T1571) Non-Standard Port — Command and Control — observed in 8 of 18 tracked threats

## Tracked threats

- [Evolution of Web3 in Cloud Supply Chain Attacks: Blockchain Smart-Contract C2 (EtherHiding, TxDataHiding, NullReceiver) in DPRK-Linked npm/Go/Packagist/Rust Campaigns](https://intel.threadlinqs.com/threat/TL-2026-3023) — HIGH
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — HIGH
- [Hackers poison arrayref Rust crate (0.3.10) via proc-macro1 typosquat to push DPRK-linked cross-platform infostealer backdoor at compile time](https://intel.threadlinqs.com/threat/TL-2026-2089) — CRITICAL
- [Rust Supply Chain Attack on arrayref: Malicious Crate Versions with DPRK-Linked Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2086) — CRITICAL
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via proc-macro1 Typosquat (DPRK/Sapphire Sleet)](https://intel.threadlinqs.com/threat/TL-2026-2085) — CRITICAL
- [Popular Rust Packages With 244M Downloads Compromised in Supply Chain Attack](https://intel.threadlinqs.com/threat/TL-2026-2083) — CRITICAL
- [NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages](https://intel.threadlinqs.com/threat/TL-2026-1856) — HIGH
- [Sapphire Sleet (DPRK) 'easy-day-js' Supply-Chain Compromise of 140+ Mastra npm Packages via Hijacked Maintainer Account](https://intel.threadlinqs.com/threat/TL-2026-0898) — CRITICAL
- [North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop](https://intel.threadlinqs.com/threat/TL-2026-0813) — HIGH
- [Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT Dropper](https://intel.threadlinqs.com/threat/TL-2026-0397) — CRITICAL
- [Axios npm Supply Chain Compromise (v1.14.1 / v0.30.4) Reaches OpenAI macOS Signing Pipeline, Forces Apple Certificate Rotation — DPRK UNC1069 / Sapphire Sleet WAVESHAPER.V2](https://intel.threadlinqs.com/threat/TL-2026-0351) — CRITICAL
- [Axios npm Supply Chain Compromise — WAVESHAPER.V2 Cross-Platform RAT Deployment by UNC1069/Sapphire Sleet (DPRK)](https://intel.threadlinqs.com/threat/TL-2026-0314) — CRITICAL
- [Axios npm Supply Chain Compromise by Sapphire Sleet (DPRK) — Cross-Platform RAT via Phantom Dependency](https://intel.threadlinqs.com/threat/TL-2026-0311) — CRITICAL
- [UNC1069 Compromises Axios NPM Package in Supply Chain Attack Deploying WAVESHAPER.V2 Cross-Platform Backdoor](https://intel.threadlinqs.com/threat/TL-2026-0309) — CRITICAL
- [North Korea (UNC1069) Supply Chain Compromise of Axios NPM Package via Backdoored plain-crypto-js Dependency](https://intel.threadlinqs.com/threat/TL-2026-0305) — CRITICAL
- [Axios NPM Supply Chain Compromise — Cross-Platform RAT via Malicious Transitive Dependency (plain-crypto-js)](https://intel.threadlinqs.com/threat/TL-2026-0303) — CRITICAL
- [Axios npm Supply Chain Attack: Cross-Platform RAT Delivery via Compromised Maintainer Credentials (GHSA-fw8c-xr5c-95f9)](https://intel.threadlinqs.com/threat/TL-2026-0301) — CRITICAL
- [Axios npm Supply Chain Attack via Malicious plain-crypto-js Dependency (Cross-Platform RAT Dropper)](https://intel.threadlinqs.com/threat/TL-2026-0300) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC1069
