🇰🇵APT38
🇰🇵 APT38 is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 22 detection use cases to this actor across 65 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-30 to 2026-07-30.
crit 1
22Use cases
1Articles
65Techniques
2IOCs
Known aliases
APT38BeagleBoyzStardust ChollimaNICKEL GLADSTONEBluenoroffSapphire SleetCOPERNICIUM
Top techniques
All other tracked techniques
T1005 · Data from Local SystemT1027.002 · Software PackingT1033 · System Owner/User DiscoveryT1036.003 · Rename Legitimate UtilitiesT1036.006 · Space after FilenameT1049 · System Network Connections DiscoveryT1053.003 · CronT1053.005 · Scheduled TaskT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1115 · Clipboard DataT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1218.005 · MshtaT1218.007 · MsiexecT1218.011 · Rundll32T1480.002 · Mutual ExclusionT1485 · Data DestructionT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1529 · System Shutdown/RebootT1543.003 · Windows ServiceT1548.002 · Bypass User Account ControlT1553.005 · Mark-of-the-Web BypassT1561.002 · Disk Structure WipeT1565.001 · Stored Data ManipulationT1565.002 · Transmitted Data ManipulationT1565.003 · Runtime Data ManipulationT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1583.001 · DomainsT1588.002 · ToolT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event LogsT1686 · Disable or Modify System FirewallT1686.002 · Network Device FirewallT1690 · Prevent Command History Logging
Detection use cases (22)
Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command Trusted vendor binary / installer launching unusual children Article-specific behavioural hunt — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet 1Password failed sign-in burst Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Package manager lifecycle hook spawns network-fetching shell or runtimeThreat-intel articles (1)
Tracked indicators
Domains (1)
npmjs.storeIP addresses (1)
216.74.123.126CVEs (1)
CVE-2026-50522