APT37 is a North Korean state-sponsored cyberespionage group active since at least 2012. It is also tracked as ScarCruft, Group123, Reaper, TEMP.Reaper, InkySquid, Ricochet Chollima, RedEyes, and TA-RedAnt. Its principal objective is intelligence collection benefiting the North Korean regime. South Korea is its primary target, with operations also extending to Japan and Vietnam. Targets include government and private-sector organizations, North Korean human-rights groups, defectors, journalists, and specialists in unification, defense, diplomacy, and North Korean affairs. Its intelligence interests include defense, aerospace, nuclear technology, and engineering. APT37 commonly obtains initial access through tailored spear-phishing messages containing malicious Hangul Word Processor or Microsoft Office documents, Windows shortcuts, and links to cloud-hosted archives. It impersonates academics, journalists, officials, and civil-society representatives, frequently displaying legitimate decoy documents. The group also conducts watering-hole attacks against websites visited by its intended targets. Documented exploitation includes the Flash vulnerability CVE-2018-4878 and Internet Explorer vulnerabilities CVE-2020-1380 and CVE-2021-26411. Its malware includes ROKRAT and BLUELIGHT, which provide remote access, reconnaissance, screenshot collection, and data exfiltration. ROKRAT supports command execution, additional payload deployment, and theft of documents and audio recordings. APT37 abuses legitimate cloud-storage APIs and Backend-as-a-Service platforms for command and control and data transfer. Its operational techniques include staged PowerShell execution, in-memory payload loading, process injection, scheduled tasks, encrypted payloads, string obfuscation, and anti-debugging and virtualization checks. It also uses email web beacons to profile prospective victims and replaces cloud-hosted malicious payloads with benign material to obstruct investigation. Beyond espionage tooling, the group has distributed destructive malware capable of damaging disk boot structures.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
65 malware families attributed to this actor across reporting.
60 additional families tracked in Mallory.
26 CVEs this actor has used in observed campaigns. 26 of them exploited in the wild.
과거에는 HWP 문서 취약점, SWF Flash Player 제로데이(CVE-2018-4878) 등 다양한 보안 취약점을 빠르게 선점해 실전 공격에 도입 적용했을 정도로 취약점 공격에 매우 능동적인 양상을 보였습니다.
The background section states that APT37 previously carried out various zero-day attacks, including exploitation of the Internet Explorer vulnerability CVE-2022-41128.
Tools Used by Group123: ... Flash Exploits, ... CVE-2016-4117 ...
2024-10-16 ⋅ AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) APT37
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
21 more CVEs tied to this actor tracked in Mallory.
854 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Annotation-only mention; no actor-specific operation or behavior is described.
Listed as an annotation to a renamed-Python-binary detection; no actor-specific campaign or behavior is described.
Referenced only as an annotated actor associated with the detection technique.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.