Skip to content
← All Threat Actors
Nation-State high North Korea (DPRK)

Sapphire Sleet (BlueNoroff)

North Korean state-sponsored (RGB — Reconnaissance General Bureau, Lazarus Group financial sub-cluster) · Financial theft — cryptocurrency and AI API credentials for DPRK sanctions evasion revenue

Reports 1
Active Since 2018
Last Reported 23 Jun 2026
Sectors Targeted finance, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • LinkedIn social engineering posing as VC investors or technical recruiters targeting crypto exchange developers
  • npm supply chain compromise — hijacking maintainer accounts to inject credential stealers into widely-used packages
  • Postinstall hook exploitation: malicious payload executes automatically on npm install without user awareness
  • Cross-platform credential exfiltration: LLM API keys (OpenAI, Anthropic, Google), cloud credentials (AWS/GCP/Azure), cryptocurrency wallet browser extensions (166 extension IDs enumerated)
  • KANDYKORN macOS backdoor for targeting engineers at crypto exchange platforms
  • RustBucket — Rust-based macOS backdoor delivered via fake PDF job documents
  • Persistence across platforms: Windows registry Run keys, macOS LaunchAgents, Linux systemd services

Known Targets

Cryptocurrency exchange engineers and developersAI/LLM development organisations (Mastra AI npm compromise, June 2026)Venture capital firms investing in crypto and AIBlockchain and DeFi platformsFinancial technology companies

Analyst Notes

Sapphire Sleet is Lazarus Group's financial crime specialisation, focused on cryptocurrency and developer supply chain attacks. The June 2026 Mastra AI npm compromise — 144 packages updated with credential-stealing malware in under 90 minutes — specifically targeted LLM API keys alongside cryptocurrency wallets, reflecting an expanding mandate as AI infrastructure becomes financially valuable. Historical operations include the $625M Ronin Network breach (2022). All collection funds DPRK's weapons programme. See also: Lazarus Group (parent cluster) and Lazarus Group (TraderTraitor / APT38 / UNC4736).

Also Known As

BlueNoroffAPT38 (partial overlap — SWIFT/banking focus)Stardust ChollimaTA444