Threat Actor
BlueNoroff
- First Reported
- Dec 17, 2025
- Latest Reported
- Apr 1, 2026
Reported Context (2)
- Presented as the same subgroup as TA444 and attributed by Hunt IO as the operator behind the attack; described as financially motivated and operating under DPRK direction. Axios npm Supply-Chain Attack Deployed Cross-Platform RATs; Hunt.io Links It to TA444/BlueNoroff
- The article reports Bluenoroff-linked activity overlapping with Lazarus certificate-linked infrastructure; it identifies Bluenoroff as APT38. Hunt.io and Acronis Trace Lazarus and Kimsuky Infrastructure Across Campaigns
Malware (8)
People (2)
Threat Actors (4)
MITRE ATT&CK (27)
Vendors (5)
Products (8)
Tools (33)
Industries (1)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.