APT37, also known as RedEyes and ScarCruft, is a North Korea-linked espionage threat actor that has persistently targeted South Korean individuals and organizations. The group is known for spearphishing and document-based intrusion chains using Hangul Word Processor, Microsoft Office, CHM, and LNK lure files, often themed around North Korea, reunification, public-sector matters, security issues, or current events relevant to Korean targets. Reported targeting has included individuals associated with unification, education, and military-related matters, as well as broader South Korean public-sector interests. The actor has repeatedly used malware families and tooling associated with surveillance and intelligence collection, including RokRAT and M2RAT. Its operations commonly rely on PowerShell, CMD, mshta, malicious macros, embedded scripts, and decoy documents to execute payloads while reducing user suspicion. APT37 has exploited CVE-2017-8291 in Hangul EPS processing and has used steganography to conceal payloads inside image files. Persistence has been established through Run and RunOnce autoruns, and later-stage malware has included process injection into legitimate processes. APT37 tradecraft includes reconnaissance, command execution, file upload and download, registry modification, scheduled-task abuse, screenshot capture, keylogging, and theft of documents and other host data. RokRAT variants attributed to the group have used cloud platforms and APIs for command-and-control and exfiltration, including services such as OneDrive, Dropbox, pCloud, Yandex, GitHub, and Ably, reflecting a pattern of abusing legitimate web services for stealth and resilience. The group has also used CHM and LNK delivery chains that unpack embedded decoys and malicious components, sometimes executing payloads in a fileless manner. The actor’s activity is consistent with strategic intelligence collection rather than financially motivated crime. Its malware and infrastructure patterns, victimology, and long-running focus on South Korean themes align with a state-sponsored espionage mission. Known aliases include RedEyes, Red Eyes, and ScarCruft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
ASEC(AhnLab Security Emergengy response Center) 분석팀은 지난 1월 RedEyes 공격 그룹(also known as APT37, ScarCruft)이 한글 EPS(Encapulated PostScript) 취약점(CVE-2017-8291)을 통해 악성코드를 유포하는 정황을 확인하였다.
마이크로소프트는 8월 13일(미국 현지 시각 기준) 정기 패치에서 해당 취약점에 대해 공식 CVE 코드(CVE-2024-38178, CVSS 7.5)를 발급하고 관련 패치도 완료했다. 해당 취약점은 IE의 자바스크립트 엔진(jscript9.dll)으로 최적화 과정 중 데이터 타입을 잘못 해석해 Type Confusion이 발생함으로써 취약 발현이 가능해진다.
61 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting malware delivery campaigns via oversized malicious LNK shortcut files targeting South Korean users, especially individuals related to North Korea, to deploy the RokRAT backdoor for information theft and remote command execution.
Mentioned as an example of a threat group using Go-based malware, including a backdoor abusing the Ably service.
Distributing CHM malware themed around a domestic current-event lure and using it to establish persistence and execute backdoor functionality associated with the group's M2RAT intrusion chain.
Malicious LNK and CHM-based delivery campaign using mshta and PowerShell to fetch additional scripts, establish persistence via RunOnce registry keys, communicate with C2, and execute commands for reconnaissance, file transfer, registry modification, and plugin/download execution. The activity is explicitly linked to previously reported RedEyes/ScarCruft/APT37 tradecraft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.