🇰🇵

BlueNoroff

High ConfidenceCritical Threat

APT38 • Stardust Chollima • BeagleBoyz • Sapphire Sleet • COPERNICIUM

BlueNoroff is a North Korean threat actor and a subgroup of the larger Lazarus Group, specifically focused on financial gain to support the DPRK regime. Active since at least 2014, the group has conducted sophisticated attacks against banks, cryptocurrency exchanges, and financial institutions worldwide. BlueNoroff was responsible for the 2016 Bangladesh Bank heist that attempted to steal $951 million through SWIFT network manipulation. The group continues to target cryptocurrency platforms and DeFi protocols, generating hundreds of millions of dollars for North Korea's weapons programs.

Origin: North Korea
Sponsor: RGB (Reconnaissance General Bureau)
Active: 2014 - Present
Victims: 100+ financial institutions
Advanced
Active
Financial Gain
Risk Assessment
89
Composite Risk Score
Critical Risk
ARCS Compliance90
Escalation Risk88
Grievance Index92
Infrastructure Impact85
History & Evolution

BlueNoroff is a North Korean threat actor and a subgroup of the larger Lazarus Group, specifically focused on financial gain to support the DPRK regime. Active since at least 2014, the group has conducted sophisticated attacks against banks, cryptocurrency exchanges, and financial institutions worldwide. BlueNoroff was responsible for the 2016 Bangladesh Bank heist that attempted to steal $951 million through SWIFT network manipulation. The group continues to target cryptocurrency platforms and DeFi protocols, generating hundreds of millions of dollars for North Korea's weapons programs.

Targeting

Target Sectors

Financial ServicesCryptocurrencyBanksFinTech

Target Regions

GlobalSoutheast AsiaLatin AmericaAfrica
Attribution & Affiliations

Attributed to RGB (Reconnaissance General Bureau) (North Korea). Attribution confidence: High.

Intelligence Assessment
Critical
Threat Level
Highly
Targeting
Highly
Adaptability
Very High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

BlueNoroff is expected to continue operations targeting Financial Services sectors.

Timeline of Key Events
2014
Major

First observed activity of BlueNoroff

2024
Moderate

Continued active operations