All actors

APT38

Also reported as NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet and 1 other name.

Reports
199
Last reported
Known CVEs
101
Techniques in ATT&CK
56
ID
G0082
Sources
ATT&CK
Merge evidence
0 alias matches

Reports per quarter

  1. 2010 Q2: 1 report
  2. 2010 Q3: no reports
  3. 2010 Q4: no reports
  4. 2011 Q1: no reports
  5. 2011 Q2: no reports
  6. 2011 Q3: 2 reports
  7. 2011 Q4: no reports
  8. 2012 Q1: no reports
  9. 2012 Q2: no reports
  10. 2012 Q3: no reports
  11. 2012 Q4: no reports
  12. 2013 Q1: no reports
  13. 2013 Q2: no reports
  14. 2013 Q3: 1 report
  15. 2013 Q4: no reports
  16. 2014 Q1: no reports
  17. 2014 Q2: no reports
  18. 2014 Q3: no reports
  19. 2014 Q4: no reports
  20. 2015 Q1: no reports
  21. 2015 Q2: 3 reports
  22. 2015 Q3: 1 report
  23. 2015 Q4: no reports
  24. 2016 Q1: no reports
  25. 2016 Q2: 3 reports
  26. 2016 Q3: no reports
  27. 2016 Q4: 1 report
  28. 2017 Q1: 1 report
  29. 2017 Q2: 8 reports
  30. 2017 Q3: 3 reports
  31. 2017 Q4: 2 reports
  32. 2018 Q1: 15 reports
  33. 2018 Q2: 5 reports
  34. 2018 Q3: 4 reports
  35. 2018 Q4: 4 reports
  36. 2019 Q1: 14 reports
  37. 2019 Q2: 2 reports
  38. 2019 Q3: 2 reports
  39. 2019 Q4: 8 reports
  40. 2020 Q1: 5 reports
  41. 2020 Q2: 2 reports
  42. 2020 Q3: 7 reports
  43. 2020 Q4: 1 report
  44. 2021 Q1: 6 reports
  45. 2021 Q2: 4 reports
  46. 2021 Q3: 6 reports
  47. 2021 Q4: 1 report
  48. 2022 Q1: 6 reports
  49. 2022 Q2: 10 reports
  50. 2022 Q3: 3 reports
  51. 2022 Q4: 4 reports
  52. 2023 Q1: 4 reports
  53. 2023 Q2: 6 reports
  54. 2023 Q3: 1 report
  55. 2023 Q4: 4 reports
  56. 2024 Q1: no reports
  57. 2024 Q2: 2 reports
  58. 2024 Q3: no reports
  59. 2024 Q4: 1 report
  60. 2025 Q1: 1 report
  61. 2025 Q2: 3 reports
  62. 2025 Q3: 1 report
  63. 2025 Q4: 1 report
  64. 2026 Q1: 1 report
  65. 2026 Q2: 37 reports
  66. 2026 Q3: 2 reports
Dated reports, 2010 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 89 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 23 techniques Show fewer

CVEs named in reports

Show all 101 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Bankshot (Malware Family)

    date ORKL added it fromORKL

Show all 199 reports Show fewer
  1. Subgroup: Bluenoroff, APT 38, Stardust Chollima

    date ORKL added it fromORKL

  2. WannaCryptor (Malware Family)

    date ORKL added it fromORKL

  3. Bluenoroff’s RustBucket campaign

    date in the title fromORKL

  4. BlueNoroff introduces new methods bypassing MoTW

    date in the title fromORKL

  5. The DPRK delicate sound of cyber

    date in the title fromORKL

  6. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  7. APT trends report Q2 2020

    date in the title fromORKL

  8. The Hermit Kingdom’s Ransomware play

    date in the title fromORKL

  9. Spring4Shell (CVE-2022-22965)- details and mitigations

    date in the title fromORKL

  10. Lazarus Trojanized DeFi app for delivering malware

    file creation date Kaspersky fromORKL

  11. Lazarus Trojanized DeFi app for delivering malware

    date in the title fromORKL

  12. Threat Hunting for Malicious PowerShell Usage in Gigasheet

    date in the title fromORKL

  13. The BlueNoroff cryptocurrency hunt is still on

    date in the title fromORKL

  14. PseudoManuscrypt- a mass-scale spyware attack campaign

    date in the title fromORKL

  15. Exploitation of the CVE-2021-40444 vulnerability in MSHTML

    date in the title fromORKL

  16. APT_trends_report_Q2_2021_Securelist

    file creation date fromORKL

  17. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  18. North Korean Cyberattacks A Dangerous and Evolving Threat 2

    date in the CCS '25 data Heritage.org fromORKLCCS '25 data

  19. The Incredible Rise of North Korea’s Hacking Army

    date in the title fromORKL

  20. Malicious code in APKPure app

    date in the title fromORKL

  21. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  22. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  23. The many personalities of Lazarus

    date in the title fromORKL

  24. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  25. APT trends report Q2 2020

    date in the title fromORKL

  26. Looking at Big Threats Using Code Similarity. Part 1

    date in the title fromORKL

  27. Lexfo-WhitePaper-The_Lazarus_Constellation

    file creation date fromORKL

  28. Malware Analysis Report (AR20-045C)

    date in the title fromORKL

  29. APT Trends Report Q2 2018

    file creation date Kaspersky fromORKL

  30. LAZARUS_GAZE_APT38

    file creation date fromORKL

  31. Is Lazarus-APT38 Targeting Critical Infrastructures-

    date in the title fromORKL

  32. Is Lazarus_APT38 Targeting Critical Infrastructures _ – Marco Ramilli Web Corner

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  33. Fully equipped Spying Android RAT from Brazil- BRATA

    date in the title fromORKL

  34. APT-Attacks-eng.pdf

    file creation date fromORKL

  35. rpt-mtrends-2019.pdf

    file creation date fromORKL

  36. The return of the BOM

    date in the title fromORKL

  37. APT38 DYEPACK FRAMEWORK

    date in the CCS '25 data GitHub fromCCS '25 data

  38. Report2019GlobalThreatReport

    file creation date fromORKL

  39. The fourth horseman- CVE-2019-0797 vulnerability

    date in the title fromORKL

  40. APT Trends report Q2 2017

    file creation date fromORKL

  41. rpt-mtrends-2019

    file creation date fromORKL

  42. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  43. 2018 APT Summary Report CN version

    file creation date fromORKL

  44. APT38

    date in the title fromORKL

  45. A new exploit for zero-day vulnerability CVE-2018-8589

    date in the title fromORKL

  46. rpt-apt38-2018-web_v4

    file creation date fromORKL

  47. VB2018 - Who Was Not Responsible for Olympic Destroyer

    date in the title fromORKL

  48. Loki Bot- On a hunt for corporate passwords

    date in the title fromORKL

  49. KeyPass ransomware

    date in the title fromORKL

  50. APT Trends Report Q2 2018

    date in the title fromORKL

  51. Who’s who in the Zoo

    date in the title fromORKL

  52. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  53. APT Trends report Q1 2018

    date in the title fromORKL

  54. OlympicDestroyer is here to trick the industry

    date in the title fromORKL

  55. The devil’s in the Rich header

    date in the title fromORKL

  56. OlympicDestroyer is here to trick the industry - Securelist

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  57. Who Wasn’t Responsible for Olympic Destroyer-

    date in the title fromORKL

  58. A Look into the Lazarus Group’s Operations

    date in the title fromORKL

  59. APT38

    date in the CCS '25 data FireEye fromCCS '25 data

  60. Advanced Persistent Threat Groups

    date in the title fromORKL

  61. 2017 HITB A Deep Dive_release

    file creation date fromORKL

  62. ExPetr-Petya-NotPetya is a Wiper, Not Ransomware

    date in the title fromORKL

  63. Dvmap- the first Android malware with code injection

    date in the title fromORKL

  64. Lazarus under the Hood

    date in the title fromORKL

  65. Gaza cybergang, where’s your IR team-

    date in the title fromORKL

  66. The Spring Dragon APT

    date in the title fromORKL

  67. The Icefog APT- A Tale of Cloak and Three Daggers

    date in the title fromORKL

  68. Cybercriminals switch from MBR to NTFS

    date in the title fromORKL

  69. Heloag has rather no friends, just a master

    date in the title fromORKL

Newest first. Details opens the report in Explore.