🇰🇵Bluenoroff
🇰🇵 Bluenoroff is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 12 detection use cases to this actor across 46 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2026-04-09 to 2026-07-30.
crit 3high 1
12Use cases
4Articles
46Techniques
10IOCs
Known aliases
BluenoroffSapphire SleetTA444
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.007 · Proc FilesystemT1005 · Data from Local SystemT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or LocationT1059.001 · PowerShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1098.001 · Additional Cloud CredentialsT1105 · Ingress Tool TransferT1176 · Software ExtensionsT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.001 · Launch AgentT1543.002 · Systemd ServiceT1546 · Event Triggered ExecutionT1552.001 · Credentials In FilesT1555.001 · KeychainT1555.003 · Credentials from Web BrowsersT1562.001 · T1562.001T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.004 · Spearphishing VoiceT1567 · Exfiltration Over Web ServiceT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1571 · Non-Standard PortT1573 · Encrypted ChannelT1583.001 · Domains
Detection use cases (12)
Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command Trusted vendor binary / installer launching unusual children Article-specific behavioural hunt — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet BlueNoroff ClickFix Defender tamper: exclude C:\Users + disable realtime monitoring BlueNoroff typosquatted Zoom/Teams infrastructure network contactThreat-intel articles (4)
Tracked indicators
Domains (7)
callsdk.online hwsrv-1327785.hostwindsd hwsrv-1327786.hostwindsd npmjs.store us.zoom.06webin.us weekly-up.online zoom.05ukweb.ukIP addresses (3)
216.74.123.126 23.254.164.123 23.254.164.92CVEs (1)
CVE-2026-50522