🇰🇵Bluenoroff
🇰🇵 Bluenoroff is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 71 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-05-14 to 2026-05-14.
crit 1
26Use cases
1Articles
71Techniques
1IOCs
Known aliases
BluenoroffSapphire SleetTA444APT38NICKEL GLADSTONEBeagleBoyzStardust ChollimaCOPERNICIUM
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1021.002 · SMB/Windows Admin SharesT1027.002 · Software PackingT1033 · System Owner/User DiscoveryT1036.003 · Rename Legitimate UtilitiesT1036.006 · Space after FilenameT1049 · System Network Connections DiscoveryT1053.003 · CronT1055 · Process InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1105 · Ingress Tool TransferT1106 · Native APIT1110 · Brute ForceT1112 · Modify RegistryT1115 · Clipboard DataT1135 · Network Share DiscoveryT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1218.001 · Compiled HTML FileT1218.005 · MshtaT1218.007 · MsiexecT1218.010 · Regsvr32T1218.011 · Rundll32T1480.002 · Mutual ExclusionT1485 · Data DestructionT1486 · Data Encrypted for ImpactT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1529 · System Shutdown/RebootT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1553.005 · Mark-of-the-Web BypassT1555.003 · Credentials from Web BrowsersT1561.002 · Disk Structure WipeT1564.003 · Hidden WindowT1565.001 · Stored Data ManipulationT1565.002 · Transmitted Data ManipulationT1565.003 · Runtime Data ManipulationT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1583.001 · DomainsT1588.002 · ToolT1685 · Disable or Modify ToolsT1685.005 · Clear Windows Event LogsT1686 · Disable or Modify System FirewallT1686.002 · Network Device FirewallT1690 · Prevent Command History Logging
Detection use cases (26)
Bluenoroff / Sapphire Sleet fake-meeting / recruiter installer chain (msiexec spawning LOLBin from crypto/VC-themed package) Bluenoroff / APT38 AppleJeus persistence: Run-key pointing at user-writable cryptocurrency-themed binary Kimsuky HelloDoor 'tdll' Run-key persistence with regsvr32 loader Kimsuky httpMalice persistence: 'Everything 1.9a-/1.8a-' Run-key or CacheDB service install Kimsuky JSE dropper: wscript -> powershell hidden + certutil -decode chain Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Scheduled task created with suspicious image / encoded args Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command Ransomware-style mass file rename / extension change 1Password failed sign-in burst Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes Package manager lifecycle hook spawns network-fetching shell or runtimeThreat-intel articles (1)
Tracked indicators
Domains (1)
female-disorder-beta-met