Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Bluenoroff

🇰🇵Bluenoroff

🇰🇵 Bluenoroff is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 71 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-05-14 to 2026-05-14.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0098) ↗
26Use cases
1Articles
71Techniques
1IOCs

Known aliases

BluenoroffSapphire SleetTA444APT38NICKEL GLADSTONEBeagleBoyzStardust ChollimaCOPERNICIUM

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1021.002 · SMB/Windows Admin SharesT1027.002 · Software PackingT1033 · System Owner/User DiscoveryT1036.003 · Rename Legitimate UtilitiesT1036.006 · Space after FilenameT1049 · System Network Connections DiscoveryT1053.003 · CronT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1115 · Clipboard DataT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1218.005 · MshtaT1218.007 · MsiexecT1218.010 · Regsvr32T1218.011 · Rundll32T1480.002 · Mutual ExclusionT1485 · Data DestructionT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1529 · System Shutdown/RebootT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1553.005 · Mark-of-the-Web BypassT1555.003 · Credentials from Web BrowsersT1561.002 · Disk Structure WipeT1564.003 · Hidden WindowT1565.001 · Stored Data ManipulationT1565.002 · Transmitted Data ManipulationT1565.003 · Runtime Data ManipulationT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1583.001 · DomainsT1588.002 · ToolT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event LogsT1686 · Disable or Modify System FirewallT1686.002 · Network Device FirewallT1690 · Prevent Command History Logging

Detection use cases (26)

Bluenoroff / Sapphire Sleet fake-meeting / recruiter installer chain (msiexec spawning LOLBin from crypto/VC-themed package) AI · profile SΣDD Bluenoroff / APT38 AppleJeus persistence: Run-key pointing at user-writable cryptocurrency-themed binary AI · profile SΣDD Kimsuky HelloDoor 'tdll' Run-key persistence with regsvr32 loader Bespoke Kimsuky httpMalice persistence: 'Everything 1.9a-/1.8a-' Run-key or CacheDB service install Bespoke Kimsuky JSE dropper: wscript -> powershell hidden + certutil -decode chain Bespoke Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Scheduled task created with suspicious image / encoded args Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal PowerShell encoded / obfuscated command Internal Ransomware-style mass file rename / extension change Internal 1Password failed sign-in burst MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access MITRE match Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes MITRE match Package manager lifecycle hook spawns network-fetching shell or runtime MITRE match

Threat-intel articles (1)

Tracked indicators

Domains (1)

female-disorder-beta-met