Dolphin is a Windows backdoor used by the North Korean espionage group APT37, also known as ScarCruft or Reaper, in highly targeted intelligence-gathering operations. It has been observed since at least 2021 as a selective second-stage payload delivered after earlier compromise components such as BLUELIGHT, including in watering-hole activity against South Korean targets. Dolphin is implemented as a C++ executable and uses cloud storage, specifically Google Drive, for command-and-control and exfiltration, allowing operators to issue tasks and retrieve stolen data through a legitimate web service.
The malware provides broad surveillance and collection capabilities. It profiles infected hosts by gathering system and user information, inspects local, removable, and portable-device storage for files of interest, and exfiltrates collected data in encrypted archives while tracking prior uploads to avoid duplication. It supports keylogging, periodic screenshot capture, browser credential and cookie theft, shell command execution, and execution of additional shellcode, including in injected processes. Dolphin has also been observed accessing data on connected smartphones through the Windows Portable Device API, reflecting a focus on harvesting documents and other sensitive material beyond the primary host.
Dolphin is deployed through a multistage loader chain that has included a downloaded Python interpreter, encrypted shellcode stages, process injection, and persistence mechanisms such as Run-key execution and scheduled task creation. Multiple versions observed between 2021 and early 2022 show ongoing development and defense-evasion refinements, including dynamic API resolution, string obfuscation, and temporary removal or later restoration of credential-theft functionality. Earlier variants also modified Google account security-related settings to help preserve access to victim email accounts after compromise. The malware is associated with espionage targeting aligned with North Korean interests, particularly organizations and individuals in South Korea and other regional targets of intelligence value.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These malicious documents exploited an Internet Explorer 0-day vulnerability in the JScript engine, CVE-2022-41128. The vulnerability resides within “jscript9.dll”, the JavaScript engine of Internet Explorer, and can be exploited to execute arbitrary code when rendering an attacker-controlled website.
ESET researchers have analyzed a previously unreported backdoor used by the ScarCruft APT group. The backdoor, which we named Dolphin, has a wide range of spying capabilities, including monitoring drives and portable devices and exfiltrating files of interest, keylogging and taking screenshots, and stealing credentials from browsers. | ScarCruft exploits CVE-2020-1380 to compromise victims.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although we did not recover a final payload for this campaign, we’ve previously observed the same group deliver a variety of implants like ROKRAT, BLUELIGHT, and DOLPHIN.
Security researchers found a previously unknown backdoor they call Dolphin that's been used by North Korean hackers in highly targeted operations for more than a year to steal files and send them to Google Drive storage.
Security researchers found a previously unknown backdoor they call Dolphin that's been used by North Korean hackers in highly targeted operations for more than a year to steal files and send them to Google Drive storage.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
To start the loading chain after installation, it creates a one-time scheduled task.
The installer downloads a CAB file from OneDrive, containing a legitimate Python 2.7 interpreter... Step 1, the Python script, reads a specified file, XOR-decrypts its contents, and executes the resulting shellcode.
MITRE ATT&CK techniques... ScarCruft used malicious JavaScript for a watering-hole attack.
To start the loading chain after installation, it creates a one-time scheduled task.
The Python loader includes a script and shellcode, launching a multi-step XOR-decryption, process creation, etc., eventually resulting in the execution of the Dolphin payload in a newly created memory process.
Step 2 (embedded in the installer) containing the rest of the loading chain, including the payload, is encrypted with a one-byte XOR key... The content is encrypted using AES CBC... Most strings in this version are base64 encoded.
Dolphin can record user keystrokes in Google Chrome by abusing the 'GetAsyncKeyState' API.
Dolphin logs keystrokes for windows with titles containing substrings specified in its configuration. The defaults are chrome and internet explore (sic). This is done via the GetAsyncKeyState API, with keystrokes being logged along with the window name and current time.
The following basic information about the computer and the backdoor is collected: ... Local and external IP address
Internet connection check added ( https://www.microsoft.com ); no malicious code is executed if offline
The following basic information about the computer and the backdoor is collected: ... Username
During the initial stage, Dolphin collects the following information from the infected machine: Username, Computer name, Local and external IP address, Installed security software, RAM size and usage, Presence of debugging or network packet inspection tools, OS version.
By default, Dolphin searches all non-fixed drives (USBs), creates directory listings and exfiltrates files by extension... Among regular drives, Dolphin also searches portable devices such as smartphones.
The malware has an extended set of capabilities that includes scanning local and removable drives for various types of data (media, documents, emails, certificates) that is archived and delivered to Google Drive.
The malware has an extended set of capabilities that includes scanning local and removable drives for various types of data (media, documents, emails, certificates) that is archived and delivered to Google Drive.
Dolphin can record user keystrokes in Google Chrome by abusing the 'GetAsyncKeyState' API.
Data staging Dolphin exfiltrates data to Google Drive storage, staging the data in encrypted ZIP archives before upload.
Dolphin now unconditionally creates directory listings and exfiltrates files by extension every 30 minutes for all drives and devices (fixed drives, removable drives, portable devices).
Its search capabilities extend to any phone connected to the compromised host by using the Windows Portable Device API.
Additionally it reports twice to the C2 server: before launching the exploit and after the exploit succeeds.
It communicates with Google Drive cloud storage, which is used as its C&C server... Dolphin uses HTTPS to communicate with Google Drive.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dolphin is a mobile backdoor associated with ScarCruft.
A mobile backdoor used by APT37 against EU-based organizations.
An implant/backdoor previously delivered by APT37; the article describes APT37 implants as using legitimate cloud services as C2 and offering standard backdoor capabilities.
A ScarCruft backdoor used for espionage. It collects system information, searches fixed/removable/portable drives for files of interest, exfiltrates data to Google Drive, logs keystrokes, captures screenshots, executes shellcode and shell commands, steals browser credentials/cookies, and in earlier versions modifies Google/Gmail account settings to reduce security and help maintain mailbox access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.