Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Bluenoroff

🇰🇵Bluenoroff

🇰🇵 Bluenoroff is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 12 detection use cases to this actor across 46 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2026-04-09 to 2026-07-30.

crit 3high 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0098) ↗
12Use cases
4Articles
46Techniques
10IOCs

Known aliases

BluenoroffSapphire SleetTA444

Top techniques

All other tracked techniques

Detection use cases (12)

Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal PowerShell encoded / obfuscated command Internal Trusted vendor binary / installer launching unusual children Internal Article-specific behavioural hunt — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Internal BlueNoroff ClickFix Defender tamper: exclude C:\Users + disable realtime monitoring Bespoke BlueNoroff typosquatted Zoom/Teams infrastructure network contact Bespoke

Threat-intel articles (4)

Tracked indicators

Domains (7)

callsdk.online hwsrv-1327785.hostwindsd hwsrv-1327786.hostwindsd npmjs.store us.zoom.06webin.us weekly-up.online zoom.05ukweb.uk

IP addresses (3)

216.74.123.126 23.254.164.123 23.254.164.92

CVEs (1)

CVE-2026-50522