APT38
Also known as: andariel, appleworm, apt 38, apt-c-26, atk117, atk3, beagleboyz, black artemis, bluenoroff, bureau 121, citrine sleet, copernicium
[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020) Active since at least 2014, [APT38](https://attack.mitre.org/groups/G0082) has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which [APT38](https://attack.mitre.org/groups/G0082) stole $81 million, as well as attacks against Bancomext (Citation: FireEye APT38 Oct 2018) and Banco de Chile (Citation: FireEye APT38 Oct 2018); some of their attacks have been destructive.(Citation: CISA AA20-239A BeagleBoyz August 2020)(Citation: FireEye APT38 Oct 2018)(Citation: DOJ North Korea Indictment Feb 2021)(Citation: Kaspersky Lazarus Under The Hood Blog 2017) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
Most affected countries
No data yet.
Most affected sectors
No data yet.
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- User Account Management (10 techniques covered)
- Execution Prevention (9 techniques covered)
- Audit (8 techniques covered)
- Restrict File and Directory Permissions (7 techniques covered)
- Behavior Prevention on Endpoint (7 techniques covered)
- Disable or Remove Feature or Program (7 techniques covered)
- Privileged Account Management (6 techniques covered)
- Restrict Web-Based Content (5 techniques covered)
MITRE ATT&CK techniques
Recent victims
No data yet.
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.