APT38
Aliases: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile ; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Open interactive actor investigation
ATT&CK techniques
Data Encrypted for ImpactT1033
System Owner/User DiscoveryT1112
Modify RegistryT1049
System Network Connections DiscoveryT1070.004
File DeletionT1056.001
KeyloggingT1518.001
Security Software DiscoveryT1543.003
Windows ServiceT1189
Drive-by CompromiseT1083
File and Directory DiscoveryT1059.003
Windows Command ShellT1059.005
Visual BasicT1529
System Shutdown/RebootT1071.001
Web ProtocolsT1105
Ingress Tool TransferT1562.003
Impair Command History LoggingT1027.002
Software PackingT1217
Browser Information DiscoveryT1070.001
Clear Windows Event LogsT1070.006
TimestompT1485
Data DestructionT1110
Brute ForceT1135
Network Share DiscoveryT1082
System Information DiscoveryT1565.002
Transmitted Data ManipulationT1561.002
Disk Structure WipeT1053.005
Scheduled TaskT1588.002
ToolT1505.003
Web ShellT1115
Clipboard DataT1562.004
Disable or Modify System FirewallT1218.011
Rundll32T1565.003
Runtime Data ManipulationT1106
Native APIT1218.001
Compiled HTML FileT1204.002
Malicious FileT1565.001
Stored Data ManipulationT1005
Data from Local SystemT1059.001
PowerShellT1053.003
CronT1566.001
Spearphishing AttachmentT1569.002
Service ExecutionT1057
Process Discovery