Executive Summary
SLOWDRIFT is a backdoor used by the Korean threat actor APT37 targeting academic and strategic organizations in South Korea. It provides remote control, persistence, and exfiltration capabilities while evading standard security defenses. Detection requires vigilant monitoring of encrypted outbound traffic and anomalous scheduling or registry activity.
Enhanced Description
SLOWDRIFT is a sophisticated backdoor weaponized by the APT37 threat group to infiltrate academic institutions and strategic organizations across South Korea. The malware was first identified in a FireEye report dated February 2018, where investigators documented its deployment against educational networks and other high‑value targets. Once a host has been compromised, SLOWDRIFT establishes a persistent foothold by installing a clandestine agent that communicates with the command‑and‑control (C2) server using encrypted channels. The backdoor is built to provide adversaries with remote control capabilities while blending in with legitimate system traffic. It can download additional payloads, exfiltrate sensitive data, and maintain persistence through scheduled tasks or registry modifications. SLOWDRIFT’s stealth tactics include obfuscating its code and leveraging native Windows binaries to evade signature‑based detection. Operationally, the malware operates as a modular trojan that supports several plug‑ins—credential harvesters, keyloggers, and payload delivery agents. APT37 frequently uses SLOWDRIFT to exfiltrate research data from universities, policy analysis from government labs, and strategic documents from defense contractors, thereby supporting their broader espionage objectives.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on a primary FireEye report citing APT37’s use of SLOWDRIFT, which lends moderate confidence to the core facts such as target type and basic capabilities. However, specific technical details like the exact command set, encryption mechanisms, or persistence methods remain partially inferred due to limited publicly available telemetry, leaving gaps in understanding its full operational profile.
SLOWDRIFT is a backdoor used by APT37 against academic and strategic victims in South Korea. (Citation: FireEye APT37 Feb 2018)