Lumu Named Leader in GigaOm NDR Radar 2026

Already have an account? Sign in

Sign in

Group

G0082

APT38

Aliases

BlueNoroff, Stardust Chollima, BeagleBoyz, Nickel Gladys, Sapphire Sleet

Type

State-Sponsored Threat Group (Nation-State)

Target

ATMs worldwide, Cryptocurrency, Financial Sectors, SWIFT Systems

Malware

DYEPACK, Hermes, KillDisk, NESTEGG, NACHOCHEESE

Country

North Korea North Korea

IoCs on Maltiverse

Maltiverse provides updated IoCs for easy SIEM/SOAR/Firewall/EDR integration.

Who is APT38?

APT38 is a North Korean state-sponsored hacking group. Most nation-state actors that focus on espionage or sabotage, APT38 steals. They operate like a criminal bank robbery crew. Their mission is to bypass sanctions and fund the North Korean regime.

They are a specialized unit within the larger Lazarus Group, but their focus is money. They are infamous for the 2016 Bangladesh Bank heist, where they escaped with $81 million through the SWIFT network. They are patient. They lurk in victim networks for months. They learn the banking workflows. Then they strike.

APT38’s Common Tactics and Tools

APT38 is characterized by ‘low and slow’ operations. They use destructive malware to cover their tracks.

  • DYEPACK: A malware framework built to manipulate banking records. It alters transaction data in local databases. This hides fraudulent SWIFT transfers from bank employees.
  • Hermes and KillDisk: APT38 uses ransomware and wipers as distractions, not for extortion. They deploy tools like Hermes and KillDisk after the theft. This destroys evidence and cripples systems.
  • Living off the Land: They dwell in networks for months. To stay hidden, they use legitimate system tools like PowerShell. This allows lateral movement without triggering antivirus alarms

How to Defend Against APT38

Defense requires protecting financial infrastructure and hunting for long-term intruders.

  • Segregate SWIFT environments: Isolate payment systems like SWIFT Alliance Access. Separate them from the corporate network. Limit internet access to the absolute minimum.
  • Monitor for destructive ‘cleanup’ behavior: Watch for destructive behavior. Deploy endpoint detection to spot disk-wiping malware. Look for overwritten Master Boot Records (MBR) or mass deletion of event logs.
  • Implement File Integrity Monitoring (FIM): APT38 changes local database files to hide theft. Use FIM to alert on any unauthorized changes to transaction logs or configurations.
  • Watch for data exfiltration: Use Network Detection and Response (NDR) to find large or strange outbound traffic. The group must move stolen funds out of the network.
  • Leverage threat intelligence: Use threat feeds to track infrastructure used by subgroups like BlueNoroff. Block their initial access attempts.

Join our pre-day 
workshop waitlist

By clicking “Submit Request” you agree to the Lumu Terms of Service and Privacy Policy.