Home/Threat Actor/Sapphire Sleet
Threat Actor

Sapphire Sleet

sapphire_sleet · north_korea · active since 2020

Sapphire Sleet (canonical Microsoft Threat Intelligence Center naming Sapphire Sleet.

Microsoft prior naming COPERNICIUM.

DTEX assessment naming CryptoCore for the BlueNoroff splinter.

operational subgroup within the broader Lazarus Group ecosystem) is a DPRK state actor active publicly since at least 2020 with primary operational mission objective of generating cryptocurrency revenue for the DPRK regime through theft, Microsoft analysis indicates $10M+ cryptocurrency theft over a six-month period per November 2024 CYBERWARCON disclosure.

operationally a splintered subgroup of BlueNoroff per DTEX assessment ("BlueNoroff splintering into TraderTraitor and CryptoCore aka Sapphire Sleet")

operationally distinct from broader DPRK-attributed clusters (andariel, apt37, apt38_bluenoroff, citrine_sleet, contagious_interview, kimsuky, lazarus_group) through signature outbound recruiter/VC-impersonation tradecraft (operationally inverse from contagious_interview's inbound DPRK-IT-worker tradecraft), fake Zoom meeting + script-delivery tradecraft, LinkedIn fake-recruiter profile impersonation pattern (impersonating Goldman Sachs and similar prestigious financial firms), skills-assessment- portal infrastructure tradecraft, multi-platform Windows + macOS malware delivery, and significant macOS-specific tradecraft maturation (April 2026 Zoom SDK Update.scpt AppleScript multi-stage payload cascade with legitimate softwareupdate-binary-invalid-parameter trust establishment, NSCreateObjectFileImageFromMemory API in-memory payload loading, icloudz backdoor mimicking legitimate iCloud artifact, Telegram Bot API credential exfiltration); signature operational sequence includes (1) VC-pose online meeting setup, (2) frozen-screen / error-message lure on meeting day, (3) "fix the connection issue" script delivery (.scpt macOS / .vbs Windows), (4) malware download, (5) cryptocurrency wallet + credential theft; AI tooling (Faceswap, voice-changer software) for operator persona enhancement.

fills DPRK cryptocurrency-theft-via- social-engineering specialization cell in the curated corpus.

north_korea confidence: high 11 aliases MITRE ATT&CK G0082 ↗
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited3

Profile

Sapphire Sleet (canonical Microsoft Threat Intelligence Center naming Sapphire Sleet.

Microsoft prior naming COPERNICIUM.

DTEX assessment naming CryptoCore for the BlueNoroff splinter.

operational subgroup within the broader Lazarus Group ecosystem) is a Democratic People's Republic of Korea (DPRK) state actor active publicly since at least 2020, with primary operational mission objective of generating cryptocurrency revenue for the DPRK regime through theft. Microsoft analysis indicates "over 10 million US dollars' worth of cryptocurrency was stolen by the threat actor from multiple companies over a six-month period" (per November 2024 CYBERWARCON disclosure). Per DTEX assessment, Sapphire Sleet is operationally a splintered subgroup of BlueNoroff (curated separately as apt38_bluenoroff.yaml in this corpus). The cluster operationally specializes in cryptocurrency theft via social engineering tradecraft and is operationally distinct from the broader Lazarus / BlueNoroff banking-focused operations. Microsoft tracks Sapphire Sleet as a distinct cluster despite the operational overlap with APT38 and BlueNoroff. Operational phases of the cluster's longitudinal history: (1) OPERATIONAL EMERGENCE AND CORE TRADECRAFT ESTABLISHMENT (2020-2022). Microsoft tracks Sapphire Sleet as "active since at least 2020." Earliest operations established the operational pattern of cryptocurrency theft via social engineering, fake LinkedIn profiles posing as recruiters or venture capitalists, multi-platform malware delivery, and DPRK regime revenue generation mission objectives. (2) VENTURE CAPITALIST + LINKEDIN RECRUITER IMPERSONATION ERA (2022-Present). Per Microsoft, "the primary scheme used by Sapphire Sleet over the past year and a half is to masquerade as a venture capitalist, feigning interest in investing in the target user's company." Fake Zoom meeting tradecraft delivers Windows VBS or macOS AppleScript malware to victims attempting to "fix" connection issues. Secondary recruiter impersonation tradecraft uses LinkedIn fake-recruiter profiles (often impersonating Goldman Sachs and similar prestigious financial-services firms) to target finance professionals with fake skills assessments hosted on attacker-controlled portals that deliver malware on sign-in. (3) SKILLS ASSESSMENT PORTAL INFRASTRUCTURE DISCLOSURE ERA (November 2023). Microsoft November 2023 disclosure established canonical tracking of the cluster's skills- assessment-portal operational tradecraft pattern. (4) CYBERWARCON $10M+ CRYPTOCURRENCY THEFT DISCLOSURE ERA (November 22, 2024). Microsoft CYBERWARCON canonical Sapphire Sleet disclosure with $10M+ six-month cryptocurrency theft attribution. AI tooling (Faceswap, voice-changer software) operator-persona enhancement documented. (5) macOS-SPECIFIC TRADECRAFT MATURATION ERA (April 2026). Significant macOS-specific tradecraft maturation operationally documented in Microsoft April 2026 disclosure: Zoom SDK Update.scpt AppleScript multi-stage payload cascade.

legitimate macOS softwareupdate binary launched with invalid parameter for trust establishment.

cascading curl-fetched AppleScript stages each with distinct user- agent strings as campaign tracking identifiers.

icloudz backdoor mimicking legitimate iCloud artifact and using NSCreateObjectFileImageFromMemory API for in-memory payload loading.

Telegram Bot API for credential exfiltration.

Signature operational tradecraft includes
  • Venture capitalist impersonation + fake Zoom meeting tradecraft: signature primary operational pattern, cluster operators pose as VCs interested in investing in target's company, set up online meetings, and deliver Windows VBS or macOS AppleScript malware via "fix the connection issue" social engineering.
  • LinkedIn fake-recruiter-profile impersonation: signature secondary operational pattern, impersonating recruiters from Goldman Sachs and other prestigious financial-services firms, delivering malware via fake skills-assessment portals.
  • Skills assessment portal infrastructure: signature operational infrastructure pattern, attacker-controlled portals legitimately-styled to appear as skills-assessment tools for finance/cryptocurrency professional candidates.
  • Multi-platform malware delivery (Windows + macOS): signature pattern of delivering platform-appropriate malware (.vbs for Windows, .scpt for macOS) based on target's environment.
  • macOS-specific tradecraft maturation (April 2026): AppleScript multi-stage payload cascade, legitimate softwareupdate-binary-with-invalid-parameter trust establishment, NSCreateObjectFileImageFromMemory API for in-memory payload loading, icloudz backdoor with legitimate-artifact masquerading.
  • Telegram Bot API credential exfiltration: signature C2 channel for credential exfiltration, operationally consistent with broader DPRK cluster patterns of legitimate-service abuse for C2.
  • AI tooling for operator persona enhancement: Faceswap for fake-profile photo alteration, voice-changer software, operationally improving social-engineering effectiveness.
  • Cryptocurrency wallet credential theft as primary mission: operationally distinct from competing DPRK clusters with broader banking-credential-theft missions.
  • Outbound social engineering operational pattern: operationally inverse from contagious_interview's inbound DPRK-IT-worker-posing-as-candidate tradecraft, Sapphire Sleet operates outbound, posing as employers/recruiters/ investors targeting individuals. The cluster fills the DPRK cryptocurrency-theft-via-social- engineering specialization cell in this curated corpus, complementing the broader DPRK-attributed cluster coverage (andariel, apt37_reaper, apt38_bluenoroff, citrine_sleet, contagious_interview, kimsuky, lazarus_group). Sapphire Sleet is operationally distinct from these adjacent DPRK-attributed clusters through (a) signature outbound recruiter/VC-impersonation tradecraft (operationally inverse from contagious_interview's inbound DPRK-IT-worker tradecraft); (b) signature fake Zoom meeting + script- delivery tradecraft; (c) signature LinkedIn fake-recruiter profile impersonation pattern; (d) signature skills- assessment-portal infrastructure tradecraft; (e) signature multi-platform Windows + macOS malware delivery; (f) signature macOS-specific tradecraft maturation (April 2026 Zoom SDK Update.scpt campaign).

Aliases

11
sapphire sleetsapphire-sleetsapphire_sleetcoperniciumcryptocorecrypto coreunc4736_partial_overlapbluenoroff_subgroupapt38_overlapsapphire_sleet_dprksapphire sleet (lazarus subgroup)

MITRE ATT&CK aliases

5
Additional names MITRE lists for G0082.
APT38NICKEL GLADSTONEBeagleBoyzBluenoroffStardust Chollima

Notable Campaigns

8
2026macOS Zoom SDK Update.scpt AppleScript Campaign (April 2026)
2024-2026Continued Operations Through 2026 (Persistent DPRK Revenue Generation Mission)
2024Microsoft CYBERWARCON Disclosure, $10M+ Cryptocurrency Theft (November 22, 2024)
2024AI Tooling for Operator Persona Enhancement (2024)
2023Skills Assessment Portal Infrastructure Disclosure (November 2023)
2020-2026Venture Capitalist Impersonation Tradecraft (Active Since 2020)
2020-2026LinkedIn Recruiter Impersonation Tradecraft (Active Since 2020)
2020Sapphire Sleet Operational Emergence (2020)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence CenterMandiantGoogle Cloud Threat IntelligenceCrowdStrikeDTEX SystemsSOPHOS X-OpsTrend MicroSymantec / Broadcom Threat Hunter TeamSentinelOne / SentinelLabsRecorded Future Insikt GroupVolexityKaspersky GReATApple Threat Intelligence (via Microsoft disclosure)US Treasury Office of Foreign Assets Control (OFAC)US FBIUS CISAUS State Department Rewards for Justice
Key reporting
reportMicrosoft Threat Intelligence Center: Microsoft Shares Latest Intelligence on North Korean and Chinese Threat Actors at CYBERWARCON (November 22, 2024), canonical $10M+ cryptocurrency theft disclosure
reportMicrosoft Threat Intelligence Center: North Korea Targets macOS Users in Latest Heist, Zoom SDK Update.scpt Campaign Analysis (April 2026)
reportMicrosoft Threat Intelligence Center: Sapphire Sleet Skills Assessment Portal Infrastructure Disclosure (November 2023)
reportDTEX Systems: DPRK Cyber Attribution Analysis, BlueNoroff Splintering into TraderTraitor and CryptoCore (aka Sapphire Sleet)
reportMandiant: North Korean Cryptocurrency Threats Continued Tracking
reportCrowdStrike: Labyrinth Chollima Evolution Analysis, Three-Cluster Splintering (Core / Golden Chollima / Pressure Chollima)
reportSOPHOS X-Ops: DPRK Threat Cluster Tracking
reportTrend Micro: DPRK Cluster Tracking
reportSymantec / Broadcom Threat Hunter Team: DPRK Cluster Continued Tracking
reportSentinelLabs: DPRK Cluster Operational Analysis
reportRecorded Future Insikt Group: DPRK Cyber Operations Tracking
reportVolexity: DPRK Cluster Operational Profile
reportKaspersky GReAT: DPRK Cluster Tracking
reportApple Threat Intelligence: Sapphire Sleet macOS Targeting Disclosure (via Microsoft disclosure April 2026)
reportUS Department of the Treasury OFAC: DPRK Cyber Sanctions
reportUS FBI: The Iran Threat / DPRK Threat Analyses
reportUS Department of State Rewards for Justice: DPRK Cluster Operator Bounties
reportMITRE ATT&CK Group G1015, Sapphire Sleet

Operational

State sponsor

Democratic People's Republic of Korea (DPRK) state actor, Microsoft Threat Intelligence Center tracks Sapphire Sleet as one of multiple DPRK-attributed cyber threat clusters within the broader DPRK cyber apparatus. The cluster operates within the broader Lazarus Group ecosystem (also known as Diamond Sleet, Hidden Cobra) which is formally attributed to the DPRK Reconnaissance General Bureau (RGB). Per DTEX assessment, Sapphire Sleet is operationally a splintered subgroup of BlueNoroff (curated separately as apt38_bluenoroff.yaml), BlueNoroff "splintering into TraderTraitor and CryptoCore (aka Sapphire Sleet)" with Sapphire Sleet specializing in cryptocurrency theft via social engineering tradecraft and CryptoCore being the adjacent naming for the same operational specialization. The cluster's primary operational mission is generating cryptocurrency revenue for the DPRK regime through theft, Microsoft analysis of Sapphire Sleet activity indicates that "over 10 million US dollars' worth of cryptocurrency was stolen by the threat actor from multiple companies over a six-month period" (per November 2024 Microsoft CYBERWARCON disclosure). The cluster operates within the broader DPRK cyber apparatus pattern of using cyber operations to generate hard-currency revenue to fund the regime's weapons programs in light of international sanctions. CrowdStrike subsequent analysis suggests the broader Lazarus Group has "evolved into three separate clusters with distinct objectives and tradecraft: the core Labyrinth Chollima group, Golden Chollima (aka AppleJeus, Citrine Sleet, and UNC4736), and Pressure Chollima (aka Jade Sleet, TraderTraitor, and UNC4899)", with the financial-cryptocurrency-theft-via-social-engineering operational specialization spread across multiple sub- clusters. The cluster is operationally distinct from the broader DPRK-attributed clusters already curated in this corpus (andariel, apt37_reaper, apt38_bluenoroff, citrine_sleet, contagious_interview, kimsuky, lazarus_group) through (a) signature recruiter / venture-capitalist impersonation tradecraft (outbound social engineering, operationally inverse from contagious_interview's inbound DPRK-IT-worker-posing-as-candidate tradecraft)

(b) signature fake Zoom meeting + script-delivery tradecraft; (c) signature LinkedIn fake-recruiter-profile-impersonation pattern (impersonating recruiters from Goldman Sachs and similar prestigious financial firms)

(d) signature skills- assessment-portal-infrastructure operational tradecraft; (e) signature multi-platform malware delivery (Windows VBS + macOS AppleScript .scpt files)

(f) recent macOS-specific targeting maturation including the April 2026 Zoom SDK Update.scpt AppleScript abuse campaign with NSCreateObject- FileImageFromMemory in-memory payload loading.

Motivations
cryptocurrency_theft, dprk_regime_revenue_generation, cryptocurrency_wallet_credential_theft, blockchain_industry_intellectual_property_theft, cryptocurrency_trading_platform_intellectual_property_theft, finance_professional_targeting, venture_capital_industry_social_engineering
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)27/60 · 45%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
METERPRETERSAPPHIRE SLEET APPLESCRIPT LOADERSSAPPHIRE SLEET MACOS PAYLOADSAPPHIRE SLEET SKILLS ASSESSMENT MALWARESAPPHIRE SLEET VBS LOADERSSAPPHIRE SLEET WINDOWS PAYLOADSKILLS ASSESSMENT PORTAL INFRASTRUCTURESOFTWAREUPDATE INVALID PARAMETER LEGITIMATE PROCESS LAUNCH

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin