Home
Glossary
Bluenoroff
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

Bluenoroff (aka Gleaming Pisces or APT38) threat actor

Bluenoroff is a North Korea-nexus threat actor whose purpose is to make money for the North Korean state. Unlike espionage groups that steal information, Bluenoroff steals funds, and it has spent years doing so at scale: first against banks and the financial messaging systems they depend on, and since around 2017 with a marked focus on cryptocurrency exchanges, blockchain and Web3 companies, and the venture capital ecosystem around them. It's generally described as a cluster within the broader set of North Korean operations often labelled the Lazarus Group, and it's also tracked as Gleaming Pisces, among other names. The distinction matters for defenders. A group tasked with revenue generation behaves differently from one tasked with intelligence collection: it goes where the money is reachable, it targets the individuals who can move funds as readily as the institutions holding them, and it keeps going, because the requirement doesn't expire. This page covers Bluenoroff's names, its relationship to Lazarus, its attribution, what it targets, how it operates, and how organizations defend against it, drawing on first-party research by Sekoia's Threat Detection & Research (TDR) team.

Key takeaways

  • Bluenoroff exists to generate revenue. Its mission is funding the North Korean state, which makes it financially motivated rather than an espionage actor.
  • It's part of the wider North Korean cyber apparatus. Usually described as a cluster within what many track as the Lazarus Group, and subject to United States sanctions since 2019.
  • Cryptocurrency and finance are its focus. Banks and financial infrastructure historically, and since around 2017 crypto exchanges, blockchain and Web3 firms, and the investment community around them.
  • Social engineering is its way in. Fabricated investment and recruitment approaches, professional network personas, and lure documents rather than exploitation of software flaws.
  • It develops across platforms. The group has extended beyond Windows to macOS, which broadens who it can reach in an industry where macOS is common.

Bluenoroff's other names

Several research teams have tracked this activity independently, and the naming is genuinely tangled because the boundaries each team draws around North Korean activity differ. The designations you'll encounter include:

  • Gleaming Pisces
  • APT38
  • Stardust Chollima
  • TA444
  • Sapphire Sleet
  • NICKEL GLADSTONE
  • COPERNICIUM

Treat these as overlapping rather than strictly interchangeable. Some designations cover exactly the financially motivated activity described here, while others are drawn more broadly or more narrowly around related North Korean clusters. Sekoia's own analysts have documented the practical consequence: malware samples tied to this activity are sometimes labelled with names belonging to other North Korean clusters, which reflects genuine difficulty separating overlapping operations rather than sloppy analysis. When researching, cross-reference designations and check what activity a given report actually describes.

How Bluenoroff relates to the Lazarus Group

Bluenoroff is commonly described as a subgroup of the Lazarus Group, and that's a reasonable shorthand, but it's worth understanding what it does and doesn't mean. Lazarus is less a single team than an umbrella label applied to North Korean state cyber activity, itself associated with the Reconnaissance General Bureau, the country's principal intelligence organization. Within that structure, different clusters have different assignments. Sekoia's assessment places Bluenoroff as subordinated to Bureau 121 and tasked with revenue generation since at least 2015.

So the useful mental model isn't a hierarchy with Bluenoroff reporting to a Lazarus manager. It's a state programme with divided labour, where one cluster pursues intelligence, another pursues destruction or disruption, and this one pursues money. Tooling, infrastructure, and people can be shared across them, which is exactly why attribution between clusters is difficult and why vendor naming diverges.

Attribution

Bluenoroff is attributed to North Korea, and that attribution is a matter of public record rather than industry assessment alone. In September 2019 the United States Treasury designated Bluenoroff by name, alongside the Lazarus Group and a third cluster, as agents of the North Korean government, citing financially motivated operations against financial institutions. United States authorities also use the designation Hidden Cobra for North Korean malicious cyber activity more broadly, and successive United Nations reporting has documented how funds stolen through such operations support the country's weapons programmes under international sanctions.

That context explains the group's persistence better than any technical detail. Bluenoroff isn't opportunistic crime that can be deterred by making one target harder. It's a funded programme with a standing requirement, operating for a state under sanctions, and it has every reason to keep working through whatever defensive improvements the industry makes.

What Bluenoroff targets

The targeting has evolved with where value is easiest to reach, but the logic has stayed constant: money that can be moved.

Bluenoroff targets
Target Why
Banks and financial institutions The group's historical focus, including the interbank messaging systems used to authorize transfers, where a single successful intrusion can move very large sums.
Cryptocurrency exchanges and platforms The dominant focus since around 2017. Crypto offers large, concentrated holdings and transfers that are difficult to reverse once made.
Blockchain and Web3 companies Firms building in the sector, which hold both funds and the credentials and keys that control them.
Venture capital and investment firms Organizations connected to the crypto and fintech ecosystem, useful both as targets and as identities to impersonate when approaching others.
Individuals holding or moving funds Developers, executives, and finance staff, since a single person with the right access can be a faster route than the organization's perimeter.

Geographically the activity has reached organizations across Asia, North America, Europe, and the Middle East. Sekoia's analysts, examining the infrastructure the group prepared, found a concentration on Asia and the United States, which is consistent with where fintech activity is densest, and also observed preparation aimed at smaller markets in South East Asia.

How Bluenoroff operates

Bluenoroff's approach is built on persuasion rather than exploitation. Its intrusions generally begin with a person choosing to open something, which is why the group invests in making the approach credible.

  • Fabricated business approaches. Investment proposals, partnership discussions, and recruitment offers tailored to the target's role and sector, which fit naturally into how the crypto and venture community actually communicates.
  • Personas on professional networks. Accounts built to look like real industry contacts, used to open a conversation before anything malicious is sent. Sekoia identified one such profile during its own investigation, apparently used to engage targets before delivering documents through a file sharing service.
  • Lure documents and archives. Files that look like legitimate business material, delivered in archives combining a harmless document with something that executes, and requiring the target to take an extra step that a plain attachment wouldn't.
  • Typosquatted domains. Infrastructure impersonating real fund management, venture capital, crypto, and technology companies, which supports both the credibility of an approach and the hosting of what follows.
  • Cross-platform malware. Implants for Windows and, since late 2022, for macOS, which matters because macOS is common in the sector the group targets.
  • Rotating delivery methods. The group has moved through a series of file formats and infection chains over time, changing them as each becomes publicly documented and better detected.

That last point deserves emphasis, because it shapes what detection has to do. Sekoia observed the group abandoning a technique once it had been described publicly, and observed short-lived infrastructure apparently used to trial a new method before adopting it more widely. A defence built on the specific artefacts of last year's campaign will not hold.

Sekoia's research on Bluenoroff

Sekoia's TDR team investigated Bluenoroff's infrastructure in 2023, during the period when the group brought macOS into its toolset. The malware family in question, known as RustBucket, was delivered through an unusual chain: a functional but backdoored document reader, which behaved normally until it was given one specific document that acted as a key to trigger the malicious behaviour. That design makes the malware considerably harder to analyse, because a sample submitted to a sandbox without its matching document does nothing of interest.

Sekoia's contribution went beyond confirming the macOS activity. TDR analysts identified a previously undocumented Windows counterpart to the same malware, built around the same approach and sharing the same decryption key, which showed the campaign was broader than the platform it had first been observed on. Pivoting from the delivery infrastructure, the team then uncovered further servers it associated with the group with high confidence, hosting other malware and several different infection chains, and assessed that the group was trialling new methods before committing to them. Using a detection heuristic developed in house, TDR also mapped a cluster of domains impersonating real financial, investment, and blockchain organizations, and built automated trackers to follow how the group's infrastructure changed over time. The team assessed the activity as part of a long-running campaign against the cryptocurrency sector, and published detection rules and indicators with the analysis.

How to defend against Bluenoroff

Because the group leads with social engineering aimed at people rather than exploits aimed at software, defence starts with process and extends into behavioural detection:

  1. Build verification into unsolicited business approaches. Investment proposals, partnership offers, and recruitment contacts arriving cold deserve an independent check of who's actually making them, particularly in sectors this group targets.
  2. Treat documents that require an unusual step as suspicious. A file that asks you to open it with a particular application, install a reader, or enable something is a strong signal on its own, whatever the surrounding story.
  3. Cover macOS with the same rigour as Windows. Endpoint visibility and detection need to extend to macOS, since the group develops for it deliberately and many organizations monitor it less closely.
  4. Protect the people who can move funds. Apply stronger controls, phishing-resistant authentication, and out-of-band verification for transfers to the roles that hold keys or approve payments.
  5. Watch for lookalike domains. Monitoring for typosquatted variants of your own name, and of the partners and investors you deal with, catches infrastructure while it's still being prepared.
  6. Detect behaviour, not last year's indicators. Given how readily the group changes delivery methods, detection should target what happens after the lure: unexpected process execution, unfamiliar outbound connections, and credential access.

Why a revenue mandate makes this actor persistent

Most threat actors can be reasoned about economically. Criminal groups weigh effort against payoff and move to easier targets when a defence gets expensive to beat. Espionage groups pursue a requirement that eventually gets satisfied or superseded. Bluenoroff fits neither pattern. It exists to fund a state operating under sanctions, which means the requirement is permanent, the budget doesn't depend on this quarter's success, and improving your defences changes which method it uses rather than whether it comes back.

That's why the practical answer is continuity of visibility rather than a control that closes a specific door. Sekoia is a European cybersecurity vendor whose in-house TDR team has tracked this group directly, including finding a variant of its malware on a platform it hadn't been observed on and following its infrastructure as it shifted. That work feeds the Sekoia AI SOC platform, where signals across endpoint, network, identity, and cloud are correlated and matched against rules mapped to the MITRE ATT&CK framework, so the sequence that follows a convincing lure is recognized as one intrusion even when the lure and the file formats are new. Cyber threat intelligence produced by the same team is what keeps that detection current as the group rotates its methods.

For an organization in financial services, crypto, or the investment community around them, the useful stance is to assume the approach will be credible. The person who receives it will not be able to tell from the message that it's fraudulent, because that's what the group is good at. What can be arranged in advance is a verification habit that doesn't depend on judging the message, and detection that watches what happens next.