APT38

G0082

Threat group.View on attack.mitre.org

About this group

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext and Banco de Chile ; some of their attacks have been destructive.

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Techniques used56

Procedure examples56

TechniqueProcedure example
T1005
Data from Local System

APT38 has collected data from a compromised host.

T1027.002
Software Packing

APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium, to pack their implants.

T1033
System Owner/User Discovery

APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.

T1036.003
Rename Legitimate Utilities

APT38 has renamed system utilities, such as `rundll32.exe` and `mshta.exe`, to avoid detection.

T1036.006
Space after Filename

APT38 has put several spaces before a file extension to avoid detection and suspicion.

T1049
System Network Connections Discovery

APT38 installed a port monitoring tool, MAPMAKER, to print the active TCP connections on the local system.

T1053.003
Cron

APT38 has used cron to create pre-scheduled and periodic background jobs on a Linux system.

T1053.005
Scheduled Task

APT38 has used Task Scheduler to run programs at system startup or on a scheduled basis for persistence. Additionally, APT38 has used living-off-the-land scripts to execute a malicious script via a scheduled task.

T1055
Process Injection

APT38 has injected malicious payloads into the `explorer.exe` process.

T1056.001
Keylogging

APT38 used a Trojan called KEYLIME to capture keystrokes from the victim’s machine.

T1057
Process Discovery

APT38 leveraged Sysmon to understand the processes, services in the organization.

T1059.001
PowerShell

APT38 has used PowerShell to execute commands and other operational tasks.

T1059.003
Windows Command Shell

APT38 has used a command-line tunneler, NACHOCHEESE, to give them shell access to a victim’s machine. Additionally, APT38 has used batch scripts.

T1059.005
Visual Basic

APT38 has used VBScript to execute commands and other operational tasks.

T1070.004
File Deletion

APT38 has used a utility called CLOSESHAVE that can securely delete a file from the system. They have also removed malware, tools, or other non-native files used during the intrusion to reduce their footprint or as part of the post-intrusion cleanup process.

View all 56 procedure examples

Software6

Campaigns0

None recorded.

References4

  1. CISA AA20-239A BeagleBoyz August 2020 Open source
    DHS/CISA. (2020, August 26). FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks. Retrieved September 29, 2021.
  2. DOJ North Korea Indictment Feb 2021 Open source
    Department of Justice. (2021, February 17). Three North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyberattacks and Financial Crimes Across the Globe. Retrieved June 9, 2021.
  3. FireEye APT38 Oct 2018 Open source
    FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.
  4. Kaspersky Lazarus Under The Hood Blog 2017 Open source
    GReAT. (2017, April 3). Lazarus Under the Hood. Retrieved April 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.