← Back to all threat actors

APT38

Also known as NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM
Tracked as G0082

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile; some of their attacks have been destructive. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

How we source and review actor profiles
Motivation
nation-state
Sectors
financial-services, cryptocurrency
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: NICKEL GLADSTONE

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BeagleBoyz

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Bluenoroff

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Stardust Chollima

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Sapphire Sleet

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: COPERNICIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0082

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT38Canonical Name
BeagleBoyzAlias
BluenoroffAlias
COPERNICIUMAlias
NICKEL GLADSTONEAlias
Sapphire SleetAlias
Stardust ChollimaAlias
G0082Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...