Threat group.View on attack.mitre.org
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile ; some of their attacks have been destructive.
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
APT38 has collected data from a compromised host. |
| T1027.002 Software Packing |
APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants. |
| T1033 System Owner/User Discovery |
APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users. |
| T1036.003 Rename Legitimate Utilities |
APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection. |
| T1036.006 Space after Filename |
APT38 has put several spaces before a file extension to avoid detection and suspicion. |
| T1049 System Network Connections Discovery |
APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system. |
| T1053.003 Cron |
APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system. |
| T1053.005 Scheduled Task |
APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task. |
| T1055 Process Injection |
APT38 has injected malicious payloads into the `explorer.exe` process. |
| T1056.001 Keylogging |
APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine. |
| T1057 Process Discovery |
APT38 leveraged Sysmon to understand the processes, services in the organization. |
| T1059.001 PowerShell |
APT38 has used PowerShell to execute commands and other operational tasks. |
| T1059.003 Windows Command Shell |
APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts. |
| T1059.005 Visual Basic |
APT38 has used VBScript to execute commands and other operational tasks. |
| T1070.004 File Deletion |
APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.