🇰🇵Bluenoroff
🇰🇵 Bluenoroff is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 77 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-04-09 to 2026-06-16.
crit 1high 1
26Use cases
2Articles
77Techniques
4IOCs
Known aliases
BluenoroffSapphire SleetTA444APT38NICKEL GLADSTONEBeagleBoyzStardust ChollimaCOPERNICIUM
Top techniques
All other tracked techniques
T1003.007 · Proc FilesystemT1005 · Data from Local SystemT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1033 · System Owner/User DiscoveryT1036.003 · Rename Legitimate UtilitiesT1036.005 · Match Legitimate Resource Name or LocationT1036.006 · Space after FilenameT1049 · System Network Connections DiscoveryT1053.003 · CronT1053.005 · Scheduled TaskT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1115 · Clipboard DataT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1189 · Drive-by CompromiseT1204.001 · Malicious LinkT1217 · Browser Information DiscoveryT1218.001 · Compiled HTML FileT1218.005 · MshtaT1218.007 · MsiexecT1218.011 · Rundll32T1219 · Remote Access ToolsT1480.002 · Mutual ExclusionT1485 · Data DestructionT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1529 · System Shutdown/RebootT1539 · Steal Web Session CookieT1543.001 · Launch AgentT1543.002 · Systemd ServiceT1543.003 · Windows ServiceT1546 · Event Triggered ExecutionT1548.002 · Bypass User Account ControlT1552.001 · Credentials In FilesT1553.005 · Mark-of-the-Web BypassT1555.003 · Credentials from Web BrowsersT1561.002 · Disk Structure WipeT1565.001 · Stored Data ManipulationT1565.002 · Transmitted Data ManipulationT1565.003 · Runtime Data ManipulationT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.004 · Spearphishing VoiceT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1571 · Non-Standard PortT1573 · Encrypted ChannelT1583.001 · DomainsT1588.002 · ToolT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event LogsT1686 · Disable or Modify System FirewallT1686.002 · Network Device FirewallT1690 · Prevent Command History Logging
Detection use cases (26)
Bluenoroff/APT38 MOTW-evasion container chain — rundll32/regsvr32 ordinal-export DLL sideload from mounted/downloaded path Sapphire Sleet crypto-theft browser hijack — Chromium launched with --load-extension from a user-writable path by a non-browser parent npm install pulls malicious easy-day-js dropper (setup.cjs + .pkg marker files) Node dropper fetches second stage from Hostwinds raw IP 23.254.164.92:8000 Cross-platform stealer RAT C2 beacon to 23.254.164.123 easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) Mastra easy-day-js second-stage stealer payload by SHA256 Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Crypto-wallet file/keystore access by non-wallet process PowerShell encoded / obfuscated command Trusted vendor binary / installer launching unusual children 1Password failed sign-in burst Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 MinutesThreat-intel articles (2)
Tracked indicators
Domains (2)
hwsrv-1327785.hostwindsd hwsrv-1327786.hostwindsdIP addresses (2)
23.254.164.123 23.254.164.92