group
APT38 G0082
- Created
- 29 January 2019
- Last modified
- 31 July 2026
- Aliases
- APT38 · NICKEL GLADSTONE · BeagleBoyz · Bluenoroff · Stardust Chollima · Sapphire Sleet · COPERNICIUM
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0082
APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.9
APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.10
APT38 has renamed system utilities, such as rundll32.exe and mshta.exe, to avoid detection.11
APT38 has put several spaces before a file extension to avoid detection and suspicion.12
APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.13
Standing G0082
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
88th percentile · 88% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
73rd percentile · 73% of 176 ATT&CK groups have this many tactics spanned or fewer.
67th percentile · 67% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
49th percentile · 51% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0082
2044 distinct rules cover the 56 techniques recorded for this group. The 2268 technique-to-rule mappings resolve to 2044 distinct rules, because one rule can cover several techniques. 1314 Sigma · 730 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org