Emerald Sleet — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 11, 2025
Last Seen
August 10, 2026

Related Threat Clusters

  • Kimsuky Expands AI Capabilities for Cyberattacks

    The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…

    39 articles · Updated August 10, 2026
  • Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants

    The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…

    4 articles · Updated July 24, 2026
  • Five Plead Guilty in North Korean IT Worker Fraud Scheme

    Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…

    39 articles · Updated November 17, 2025
  • Lazarus Group Linked to $30M Upbit Hack in South Korea

    South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…

    100 articles · Updated November 28, 2025

Recent Intelligence Reports

  • North Korean Spy Group Kimsuky Built Offline AI Lab on Attack Servers to Analyze Stolen Files — Techtimes · August 10, 2026
  • North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms — Techtimes · July 24, 2026
  • APT37 hackers abuse Google Find Hub in Android data — Bleepingcomputer · November 11, 2025

CVSS v3.1 Breakdown