DOGCALL is a Windows malware family associated with North Korean cyber activity, particularly operations attributed to APT37 (also known as Reaper or ScarCruft). It has been linked to exploitation of Adobe Flash Player vulnerability CVE-2018-4878 and to socially engineered delivery targeting South Korean victims. Reported lures have included politically themed documents and archives related to North Korean issues, consistent with APT37’s long-running focus on South Korean government, military, policy, media, and human-rights targets.
DOGCALL functions as a surveillance-oriented implant with collection capabilities that include screenshot capture, keystroke logging, and microphone audio capture from compromised systems. It has also been reported to use legitimate cloud storage and cloud-service APIs, including platforms such as Box, Dropbox, and Yandex, for command-and-control communications, reflecting a tradecraft pattern of blending malicious traffic with trusted services.
The malware has been referenced in connection with broader APT37 tooling lineage and infrastructure patterns, including later reporting that tied related lure themes and development artifacts to the same threat ecosystem. Its observed behavior and targeting align with espionage objectives rather than disruptive or financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2018-4878 Vulnerable Products: Adobe Flash Player before 28.0.0.161 Associated Malware: DOGCALL Mitigation: Update Adobe Flash Player installation to the latest version | CVE-2018-4878 ... Associated Malware: DOGCALL
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
At that time, a malicious archive named "북한이탈주민 초빙강의 (North Korean Defector Invited Lecture) .zip" was distributed, and the malware installed through it revealed the following PDB (Program Database) information. D:\Sources\MainWork\Group2017\Sample\Release\ DogCall.pdb
10 distinct techniques documented for this family, organized by ATT&CK tactic.
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
과거 동일 방송사 작가 사칭 공격 및 유사 계열 악성코드의 PDB 아티팩트에서 식별된 악성코드명으로, 본 캠페인의 전술 재활용 및 계열 연관성 분석에 활용된다.
DogCall is referenced through PDB artifact strings from a prior APT37-related sample used for tactic reuse comparison. It is mentioned as part of related historical malware family analysis rather than as the main payload in this campaign.
Backdoor malware that captures screenshots from victim machines.
Backdoor malware capable of capturing screenshots from victim machines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.