Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

APT38

Aliases: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet, COPERNICIUM • APT38 is a North Korean threat group related to Lazarus Group, focused on financial cybercrime. They are responsible for major heists like the Bank of Bangladesh attack, targeting banks and financial institutions globally.
Profile
Malicious
Category
Threat Actor Group
Threat Type
KP
Country
apt38
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

APT38, also known as Bluenoroff, is a North Korean state-sponsored threat group specializing in financially motivated cybercrime. Attributed to the Reconnaissance General Bureau, they have been active since at least 2014, targeting banks and financial institutions worldwide. Notable operations include the 2016 Bank of Bangladesh heist, where they stole $81 million.

Aliases (6)
NICKEL GLADSTONE
Alias
BeagleBoyz
Alias
Bluenoroff
Alias
Stardust Chollima
Alias
Sapphire Sleet
Alias
COPERNICIUM
Alias
Targets (4)
Financial
Target
Banks
Target
Casinos
Target
Cryptocurrency
Target
External Sources