Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT38

🇰🇵APT38

🇰🇵 APT38 is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 22 detection use cases to this actor across 65 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-30 to 2026-07-30.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0082) ↗
22Use cases
1Articles
65Techniques
2IOCs

Known aliases

APT38BeagleBoyzStardust ChollimaNICKEL GLADSTONEBluenoroffSapphire SleetCOPERNICIUM

Top techniques

All other tracked techniques

T1005 · Data from Local SystemT1027.002 · Software PackingT1033 · System Owner/User DiscoveryT1036.003 · Rename Legitimate UtilitiesT1036.006 · Space after FilenameT1049 · System Network Connections DiscoveryT1053.003 · CronT1053.005 · Scheduled TaskT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1115 · Clipboard DataT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1218.005 · MshtaT1218.007 · MsiexecT1218.011 · Rundll32T1480.002 · Mutual ExclusionT1485 · Data DestructionT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1529 · System Shutdown/RebootT1543.003 · Windows ServiceT1548.002 · Bypass User Account ControlT1553.005 · Mark-of-the-Web BypassT1561.002 · Disk Structure WipeT1565.001 · Stored Data ManipulationT1565.002 · Transmitted Data ManipulationT1565.003 · Runtime Data ManipulationT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1583.001 · DomainsT1588.002 · ToolT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event LogsT1686 · Disable or Modify System FirewallT1686.002 · Network Device FirewallT1690 · Prevent Command History Logging

Detection use cases (22)

Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal PowerShell encoded / obfuscated command Internal Trusted vendor binary / installer launching unusual children Internal Article-specific behavioural hunt — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Internal 1Password failed sign-in burst MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access MITRE match Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes MITRE match Package manager lifecycle hook spawns network-fetching shell or runtime MITRE match

Threat-intel articles (1)

Tracked indicators

Domains (1)

npmjs.store

IP addresses (1)

216.74.123.126

CVEs (1)

CVE-2026-50522