« All threats

APT groupMITRE G0082

APT38

Also known as: andariel, appleworm, apt 38, apt-c-26, atk117, atk3, beagleboyz, black artemis, bluenoroff, bureau 121, citrine sleet, copernicium

[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020) Active since at least 2014, [APT38](https://attack.mitre.org/groups/G0082) has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which [APT38](https://attack.mitre.org/groups/G0082) stole $81 million, as well as attacks against Bancomext (Citation: FireEye APT38 Oct 2018) and Banco de Chile (Citation: FireEye APT38 Oct 2018); some of their attacks have been destructive.(Citation: CISA AA20-239A BeagleBoyz August 2020)(Citation: FireEye APT38 Oct 2018)(Citation: DOJ North Korea Indictment Feb 2021)(Citation: Kaspersky Lazarus Under The Hood Blog 2017) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. User Account Management (10 techniques covered)
  2. Execution Prevention (9 techniques covered)
  3. Audit (8 techniques covered)
  4. Restrict File and Directory Permissions (7 techniques covered)
  5. Behavior Prevention on Endpoint (7 techniques covered)
  6. Disable or Remove Feature or Program (7 techniques covered)
  7. Privileged Account Management (6 techniques covered)
  8. Restrict Web-Based Content (5 techniques covered)

MITRE ATT&CK techniques

T1486 · Data Encrypted for ImpactT1055 · Process InjectionT1033 · System Owner/User DiscoveryT1112 · Modify RegistryT1049 · System Network Connections DiscoveryT1070.004 · File DeletionT1056.001 · KeyloggingT1518.001 · Security Software DiscoveryT1543.003 · Windows ServiceT1548.002 · Bypass User Account ControlT1189 · Drive-by CompromiseT1083 · File and Directory DiscoveryT1059.003 · Windows Command ShellT1140 · Deobfuscate/Decode Files or InformationT1059.005 · Visual BasicT1529 · System Shutdown/RebootT1204.001 · Malicious LinkT1071.001 · Web ProtocolsT1105 · Ingress Tool TransferT1685 · Disable or Modify ToolsT1027.002 · Software PackingT1217 · Browser Information DiscoveryT1685.005 · Clear Windows Event LogsT1218.005 · MshtaT1070.006 · TimestompT1686 · Disable or Modify System FirewallT1485 · Data DestructionT1110 · Brute ForceT1135 · Network Share DiscoveryT1553.005 · Mark-of-the-Web BypassT1082 · System Information DiscoveryT1565.002 · Transmitted Data ManipulationT1686.002 · Network Device FirewallT1561.002 · Disk Structure WipeT1036.003 · Rename Legitimate UtilitiesT1690 · Prevent Command History LoggingT1053.005 · Scheduled TaskT1588.002 · ToolT1505.003 · Web ShellT1115 · Clipboard DataT1218.011 · Rundll32T1565.003 · Runtime Data ManipulationT1583.001 · DomainsT1106 · Native APIT1218.001 · Compiled HTML FileT1204.002 · Malicious FileT1565.001 · Stored Data ManipulationT1005 · Data from Local SystemT1059.001 · PowerShellT1053.003 · CronT1566.001 · Spearphishing AttachmentT1218.007 · MsiexecT1569.002 · Service ExecutionT1480.002 · Mutual ExclusionT1057 · Process DiscoveryT1036.006 · Space after Filename

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.