APT 38 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 17, 2025
Last Seen
November 17, 2025

APT38 is a North Korean cybercrime group linked to the Lazarus Group, specializing in financially motivated operations against banks, cryptocurrency exchanges, and other financial targets to fund the DPRK.

Overview

APT38 is a North Korean cybercrime group linked to the Lazarus Group, specializing in financially motivated operations against banks, cryptocurrency exchanges, and other financial targets to fund the DPRK. It is significant due to its persistent, state-aligned activities and its role in sanctions evasion and illicit fundraising. The included article highlights U.S. enforcement actions against North Korean IT workers involved in related fraud schemes and crypto seizures, illustrating ongoing efforts to disrupt APT38-linked funding channels.

Related Threat Clusters

  • Five Plead Guilty in North Korean IT Worker Fraud Scheme

    Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…

    39 articles · Updated November 17, 2025
  • Lazarus Group Linked to $30M Upbit Hack in South Korea

    South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…

    100 articles · Updated November 28, 2025

Recent Intelligence Reports

  • US chips away at North Korean IT worker fraud with guilty pleas, cryptocurrency seizure — Cybersecuritydive · November 17, 2025

Related Entities

CVSS v3.1 Breakdown