APT38 Un-usual Suspects
2018-10-03 • Fireeye •
Attachments
rpt-apt38-2018-web_v5.pdf (3 MB)
FireEye profiles APT38 as a financially motivated North Korean regime backed group specializing in bank intrusions and destructive operations. The report says the group has attempted to steal more than $1.1 billion, compromised more than 16 organizations in at least 13 countries, and spends extended time inside victim networks before attempting fund transfers. APT38 shares malware development resources with TEMP.Hermit but is treated as a distinct cluster focused on financial institutions, SWIFT environments, reconnaissance, evasion, and evidence destruction.
Related Actors
Related Reports
Shares tag: APT38 • Same author: Fireeye
Shares tag: APT38
Shares tag: APT38
2019-01-29 •
35% Match
#APT38
#G0082
#T1082
#T1005
#T1112
#T1115
#T1083
#T1027
#T1071
#T1204
#T1057
#T1053
#T1566
#T1059
#T1105
#T1543
#T1486
#T1135
#T1218
#T1588
#T1189
#T1049
#T1217
#T1106
#T1562
#T1070
#T1056
#T1529
#T1569
#T1033
#T1485
#T1110
#T1518
#T1561
#T1565
#T1505
Shares tag: APT38
2025-11-14 •
30% Match
Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation
USJustice
Shares tag: APT38
2025-11-14 •
30% Match
Revisiting the Lazarus Operator: Mapping Park Jin Hyok’s Digital Footprint Using StealthMole
Stealth Mole
Shares tag: APT38