Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima
29
techniques
13
software
11,635
corpus matches
profile
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
techniques
29 attributed · most-instrumented first
software
13 malware & tools attributed
Cobalt Strike
S0154
CORALDECK
S0212
DOGCALL
S0213
HAPPYWORK
S0214
KARAE
S0215
POORAIM
S0216
SHUTTERSPEED
S0217
SLOWDRIFT
S0218
WINERACK
S0219
ROKRAT
S0240
read this carefully
11,635 corpus matches is not attribution
That count is indicators which exhibit techniques APT37 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+17 more techniques
NavRAT
S0247
Final1stspy
S0355
BLUELIGHT
S0657
showing 30 of 11,635
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.