Home/Threat Actor/Citrine Sleet
Threat Actor

Citrine Sleet

citrine_sleet · north_korea · active since 2017

Citrine Sleet (Microsoft DEV-0139/DEV-1222 - Citrine Sleet; Mandiant UNC4736.

CrowdStrike Labyrinth Chollima.

AppleJeus group.

US-government Hidden Cobra) is a Democratic People's Republic of Korea (DPRK) state-sponsored cyber-financial- crime cluster attributed to Bureau 121 of the Reconnaissance General Bureau (RGB), operating as a sub-cluster within the broader Lazarus Group umbrella since at least 2017, with signature operational mission of cryptocurrency theft from individual high-net-worth holders, cryptocurrency exchanges, DeFi protocols, blockchain firms, and cryptocurrency-industry- adjacent venture capital firms.

signature tradecraft includes fake-cryptocurrency-trading-platform infrastructure, LinkedIn-based fake-recruiter social engineering, the AppleJeus trojanized-cryptocurrency-application-installer malware family, and high-cost browser-and-kernel exploit chain investment culminating in the August 2024 CVE-2024-7971 Chrome V8 zero-day + CVE-2024-38106 Windows kernel + FudModule rootkit chain (one of the most sophisticated DPRK browser- exploit-chain operations ever publicly attributed)

also attributed to the March 2023 3CXDesktopApp software-supply- chain compromise (Mandiant UNC4736 attribution) affecting approximately 6 million 3CX customers globally including critical-infrastructure-sector organizations.

north_korea confidence: high 17 aliases MITRE ATT&CK G1049 ↗

Profile

Citrine Sleet (also tracked as Microsoft DEV-0139 / DEV-1222 [legacy] and Citrine Sleet [current Tempest taxonomy], Mandiant UNC4736, CrowdStrike Labyrinth Chollima, AppleJeus group, Microsoft Nickel Academy [legacy], US-government collective Hidden Cobra) is a Democratic People's Republic of Korea (DPRK) state-sponsored cyber threat actor formally attributed by Microsoft Threat Intelligence to Bureau 121 of the Reconnaissance General Bureau (RGB). The cluster operates as a sub-cluster within the broader Lazarus Group umbrella, sharing tooling, infrastructure, and operator- membership relationships with adjacent DPRK clusters including Diamond Sleet (the Zinc/Lazarus core), Sapphire Sleet (Bluenoroff-adjacent social-engineering and cryptocurrency targeting), and Onyx Sleet (Plutonium/Andariel adjacency). The DPRK Bureau 121 RGB attribution has been formally asserted by Microsoft with high confidence based on operational infrastructure, tooling patterns, victim targeting, and operator language artifacts. Operationally Citrine Sleet is one of the most consistently cryptocurrency-focused DPRK clusters across approximately eight-plus years of tracked operations (2017-present). The cluster's signature operational mission is cryptocurrency theft from individual high-net-worth holders, cryptocurrency exchanges, cryptocurrency-wallet-software vendors, decentralized finance (DeFi) protocols, blockchain technology firms, and cryptocurrency-industry-adjacent venture capital firms, for financial gain supporting DPRK state revenue generation. Cumulative cryptocurrency theft attributed to DPRK clusters including Citrine Sleet is publicly assessed to have generated cryptocurrency proceeds in excess of approximately US$3 billion across the cluster's operational history. The proceeds support DPRK state revenue generation and are laundered through complex cryptocurrency-mixing- service and exchange-conversion operational chains per multiple US Department of Justice indictments and US Department of Treasury OFAC sanctions designations targeting DPRK cryptocurrency money laundering networks. The cluster's operationally-distinctive tradecraft signatures include: (1) FAKE-CRYPTOCURRENCY-TRADING-PLATFORM INFRASTRUCTURE. The cluster operates a sustained operational pattern of creating fake websites that masquerade as legitimate cryptocurrency trading platforms, cryptocurrency wallet software vendors, and cryptocurrency-industry-related products. The fake-platform websites distribute trojanized versions of legitimate cryptocurrency-trading applications, with the AppleJeus malware family as the signature trojanized- installer payload. The AppleJeus operations have continued across Windows and macOS target platforms from 2017 through the present. (2) LINKEDIN-BASED FAKE-RECRUITER SOCIAL ENGINEERING. The cluster conducts extensive reconnaissance of cryptocurrency- industry employees via LinkedIn and other professional social-media platforms to identify high-value targets, then delivers social-engineering lures via fake-recruiter personas offering fake job interviews, fake job applications, fake cryptocurrency-related software downloads, or fake cryptocurrency-trading platform invitations. The fake- recruiter-via-LinkedIn tradecraft is shared with adjacent DPRK clusters including Sapphire Sleet and Diamond Sleet. (3) APPLEJEUS TROJAN, SIGNATURE CRYPTOCURRENCY-WALLET-THEFT MALWARE. AppleJeus is the cluster's signature custom-developed malware family used for cryptocurrency-wallet-credential exfiltration and cryptocurrency-asset theft. AppleJeus operations have continued from initial public disclosure (Kaspersky GReAT, August 2018) through 2024-present. The AppleJeus malware family is one of the most consistent technical-attribution signals for the cluster. (4) FUDMODULE ROOTKIT, KERNEL-TAMPERING CAPABILITY SHARED WITH DIAMOND SLEET. The FudModule rootkit operates from user mode but performs direct kernel object manipulation (DKOM) through a kernel read/write primitive enabled by privilege- escalation-vulnerability exploitation. FudModule operationally bypasses kernel-level endpoint-detection-and-response Protected Process Light (PPL) mechanisms in Microsoft Defender, CrowdStrike Falcon, HitmanPro, and adjacent endpoint protection products. FudModule shared operational use between Citrine Sleet and Diamond Sleet provides the strongest technical-genealogical evidence for the two clusters operating within the broader DPRK Bureau 121 RGB umbrella under operational coordination or shared-tooling- access arrangement. (5) HIGH-COST BROWSER-AND-KERNEL EXPLOIT CHAIN INVESTMENT. The August 2024 Citrine Sleet CVE-2024-7971 zero-day exploitation (Chrome V8 type-confusion remote-code-execution paired with CVE-2024-38106 Windows kernel privilege-escalation sandbox-escape paired with FudModule rootkit in-memory loading) represents one of the most sophisticated DPRK browser-exploit-chain operations ever publicly attributed. The industry-rate-card valuation for unpatched Chrome remote-code-execution capability exceeds approximately US$100,000-$150,000.

the combination of unpatched browser RCE + unpatched Windows kernel privilege escalation + custom kernel-tampering rootkit represents operational capability investment that operationally distinguishes Citrine Sleet from financially-motivated organized-cybercrime clusters that typically rely on commodity exploitation. The cluster's 2024 operational period included three distinct FudModule- rootkit deployment chains exploiting unpatched Windows kernel privilege-escalation vulnerabilities (CVE-2024-21338 AppID.sys, CVE-2024-38193 AFD.sys, CVE-2024-38106 used in the August 2024 Chrome chain), demonstrating sustained Windows-kernel-vulnerability-research-and-exploitation capability across multiple operational campaigns. (6) SUPPLY-CHAIN COMPROMISE CAPABILITY. The March 2023 3CX VoIP software supply-chain compromise (Mandiant attribution to UNC4736 / Citrine Sleet) demonstrated the cluster's capability for sophisticated software-supply-chain operations in addition to direct-cryptocurrency-victim targeting. The 3CX compromise affected approximately 6 million 3CX customers globally including critical-infrastructure-sector organizations and originated from an earlier supply-chain compromise of the Trading Technologies X-TRADER stock-trading software (also UNC4736-attributable). The 3CX supply-chain operation established Citrine Sleet as one of only a few publicly- attributed clusters with demonstrated end-to-end supply- chain compromise operational capability, alongside Lazarus core (Diamond Sleet) and a small number of state-aligned clusters globally. The cluster's operationally consistent cryptocurrency-targeting mission, sustained operational tempo across approximately eight years of tracked operations, demonstrated high-cost browser-and-kernel exploit chain investment, demonstrated sophisticated supply-chain compromise capability, and operationally-confirmed DPRK Bureau 121 RGB state-sponsorship attribution make Citrine Sleet one of the most operationally significant DPRK financial-mission clusters in modern cyber- threat-intelligence taxonomy. The cluster fills the modern DPRK-financial-cluster cell in the curated corpus, complementing the broader Lazarus Group umbrella entry (lazarus_group.yaml), the Lazarus financial-mission sub-cluster BlueNoroff (apt38_bluenoroff.yaml), the DPRK intelligence-and-financial Andariel sub-cluster (andariel.yaml), and the DPRK intelligence-focused Kimsuky sub-cluster (kimsuky.yaml) in providing complete coverage of publicly-tracked DPRK threat- actor sub-clusters in this corpus.

Aliases

17
citrine sleetcitrinesleetdev-0139dev0139dev-1222dev1222unc4736unc-4736labyrinth chollimalabyrinthchollimaapplejeusapple_jeusapplejeus grouphidden cobranickel academynickel-academycitrine_sleet

MITRE ATT&CK aliases

2
Additional names MITRE lists for G1049.
Gleaming PiscesUNC1720

Notable Campaigns

7
2024FudModule Deployment via AppID.sys Driver Privilege Escalation (CVE-2024-21338, February 2024)
2024FudModule Deployment via AFD.sys Driver Privilege Escalation (CVE-2024-38193, August 2024)
2024Chrome V8 JavaScript Engine Zero-Day Exploitation (CVE-2024-7971, August 19, 2024)
20233CXDesktopApp Voice-over-IP Supply-Chain Compromise (March 2023)
2022FudModule Rootkit Operational Emergence (October 2022)
2017-presentSustained Longitudinal Cryptocurrency-Industry Targeting (2017 - Present)
2017-2018AppleJeus Cryptocurrency-Trojan Operational Emergence (2017-2018)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence CenterMicrosoft Security Response CenterMandiantGoogle Cloud Threat IntelligenceCrowdStrikeVolexityKaspersky GReATAvast Threat LabsCisco TalosESETSymantec / BroadcomTrellixRecorded Future Insikt GroupSentinelOneTrend MicroSecureWorksGen Threat LabsUS Cyber CommandUS CISAUS FBIUS DOJUS Department of the TreasurySouth Korean National Intelligence Service (NIS, contextual)South Korean AhnLab Security Emergency Response Center (ASEC)Japanese JPCERT/CC
Key reporting
reportMicrosoft Threat Intelligence: North Korean Threat Actor Citrine Sleet Exploiting Chromium Zero-Day (August 30, 2024), canonical industry vendor reference
reportMandiant: 3CX Software Supply Chain Compromise Attribution to UNC4736 (March-April 2023), canonical 3CX supply-chain technical attribution
reportAvast Threat Labs: Lazarus and the FudModule Rootkit Beyond BlockStorm (February-March 2024), canonical FudModule 2.0 + Kaolin RAT disclosure
reportESET: FudModule Rootkit Initial Public Disclosure (October 2022)
reportKaspersky GReAT: Operation AppleJeus, Lazarus Hits Cryptocurrency Exchange with Fake Installer and macOS Malware (August 2018), canonical AppleJeus reference
reportCISA + FBI + US Treasury AA21-048A: AppleJeus, Analysis of North Korea's Cryptocurrency Malware (February 17, 2021), canonical US-government formal attribution
reportCISA + FBI + US Treasury AA22-108A: TraderTraitor, North Korean State-Sponsored APT Targets Blockchain Companies (April 2022)
reportCrowdStrike: Labyrinth Chollima Operational Tracking (multiple years)
reportSentinelOne: SmoothOperator, Ongoing Campaign Trojanizes 3CXDesktopApp (March 2023)
reportCisco Talos: 3CXDesktopApp Supply Chain Attack Analysis (March 2023)
reportTrend Micro: 3CXDesktopApp Trojan Analysis (March 2023)
reportSecureWorks Counter Threat Unit: GOLD KINGSWOOD / Labyrinth Chollima Profile
reportVolexity: DPRK Cryptocurrency Targeting Analysis (multiple years)
reportRecorded Future Insikt Group: Citrine Sleet / Lazarus Group Operational Tracking
reportUS DOJ Multiple Indictments: North Korean Regime-Backed Programmers Conspiracy to Conduct Multiple Cyber Attacks (February 2021, December 2021, others)
reportUS Department of the Treasury OFAC: Multiple Sanctions Designations Targeting DPRK Cryptocurrency Money Laundering Networks (2020 onward)
reportMalpedia Actor Profile: AppleJeus / Citrine Sleet

Operational

State sponsor

Democratic People's Republic of Korea (DPRK) state-sponsored, attributed to Bureau 121 of the Reconnaissance General Bureau (RGB), the DPRK military intelligence agency responsible for North Korean offensive cyber operations. Citrine Sleet is operationally tracked as a sub-cluster within the broader Lazarus Group umbrella, sharing tooling, infrastructure, and operator-membership relationships with adjacent DPRK clusters tracked separately by Microsoft as Diamond Sleet (which Microsoft tracks as the Zinc-legacy cluster overlapping with Lazarus core operations), Sapphire Sleet (DPRK social-engineering-and-cryptocurrency-targeting cluster, formerly DEV-0408 / Bluenoroff overlap), and Onyx Sleet (DPRK financially-motivated and intelligence operations, formerly Plutonium / Andariel adjacency). The RGB Bureau 121 attribution has been formally asserted by Microsoft Threat Intelligence with high confidence based on operational infrastructure, tooling patterns, victim targeting, and operator language artifacts.

The cluster's financial-targeting mission specifically supports the DPRK state's cryptocurrency theft and laundering operations that have been documented by US Department of Justice indictments (multiple) and US Department of Treasury OFAC sanctions designations as generating cryptocurrency proceeds that fund DPRK weapons-of-mass-destruction development programs. Citrine Sleet was previously linked by Mandiant / Google Cloud Threat Intelligence to the March 2023 3CXDesktopApp supply-chain compromise (UNC4736 attribution), establishing operational capability for sophisticated supply-chain operations in addition to direct cryptocurrency-victim targeting. The FudModule rootkit deployed by Citrine Sleet in 2024 operations is shared tooling with Diamond Sleet, providing additional technical-genealogical evidence for the DPRK-cluster-umbrella operational relationship.

Motivations
cryptocurrency_theft, financial_gain_supporting_dprk_state_revenue, cryptocurrency_industry_intelligence_collection, supply_chain_compromise_for_downstream_cryptocurrency_targeting, sanctions_evasion_via_cryptocurrency
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)28/60 · 46%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin