Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, Group 123, Red Eyes, APT37, Venus 121 (금성121), APT 37, Operation Daybreak, Operation Erebus, Reaper Group, Venus 121, ATK4, G0067, Moldy Pisces, APT-C-28, PLAIN NEPTUNE

Description

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

TTP Summary

Reaper; Erebus; Golden Time; Evil New Year; Are you Happy?; FreeMilk; North Korean Human Rights; Evil New Year 2018

Goals & Targeting

Targeted Sectors

Healthcare
Aerospace & defense
Manufacturing
Government
Critical infrastructure

Targeted Countries / Regions

RU
CN
KR
JP
IN
middle_east

AI Analysis

· 1 week ago

Executive Summary

APT37 is a North Korean state-sponsored cyber espionage group active since at least 2012. Known for its sophisticated campaigns targeting South Korea and other countries across Asia and the Middle East, APT37 employs a wide range of tactics to steal sensitive information. The group has demonstrated a particular focus on healthcare, aerospace, government, and critical infrastructure sectors.

Goals & Targeting

APT37's strategic objectives revolve around conducting cyber espionage targeting sectors such as healthcare, aerospace & defense, manufacturing, government, and critical infrastructure. The group focuses on countries with significant political or economic interests opposing North Korea, including South Korea, Japan, India, Russia, and Middle Eastern nations. Their campaigns often involve large-scale operations aimed at stealing sensitive information and disrupting the targeted organizations.

Enhanced Description

APT37, also known as InkySquid or TEMP.Reaper, is a North Korean state-sponsored cyber espionage group that has been operational since at least 2012. The group has conducted numerous campaigns between 2016-2018, including Operation Daybreak, Golden Time, and Evil New Year. APT37 primarily targets South Korea but has also targeted other countries such as Japan, India, Russia, Nepal, China, Romania, and Kuwait. Their main objective is to gather intelligence through cyber espionage activities.

Key Capabilities

  • Advanced persistent threat (APT) tactics
  • Malware development and deployment
  • Spear-phishing attacks
  • Data exfiltration techniques
  • Process injection and persistence mechanisms

MITRE ATT&CK Tactics

Reconnaissance
Exfiltration
Defense evasion
Credential access

ATT&CK Techniques

T1053.005: Scheduled Task
T1529: System Shutdown/Reboot
T1123: Audio Capture
T1204.002: Malicious File
T1120: Peripheral Device Discovery
T1005: Data from Local System
T1055: Process Injection
T1027: Obfuscated Files or Information

Software / Tooling

DOGCALL
HAPPYWORK
KARAE
SLOWDRIFT
SHUTTERSPEED
WINERACK
NavRAT
POORAIM
ROKRAT

Campaigns & Victims

APT37 has been involved in multiple campaigns, including Operation Daybreak and Operation Erebus. These campaigns often involve large-scale spear-phishing attacks, the deployment of custom malware, and the targeting of critical infrastructure sectors. The group's operational tempo is consistent with other North Korean state-sponsored actors, with a focus on long-term espionage objectives.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Malicious scripts embedded in Office documents
  • Scheduled task creation for persistence
  • Registry modifications for malware persistence

Recommended Actions

  • Implement strong email filtering to detect spear-phishing attempts
  • Monitor for unusual scheduled tasks and process injection activities
  • Conduct regular vulnerability assessments on critical infrastructure systems
  • Use endpoint detection and response (EDR) solutions to identify malicious processes
  • Train employees on identifying phishing emails

Suggested Tags

APT
espionage
cyber espionage
government
critical infrastructure

Confidence Assessment

High confidence in the description of APT37 as a North Korean state-sponsored group, based on multiple sources and campaigns. However, some uncertainty exists regarding specific tools and techniques due to potential overlaps with other North Korean-affiliated groups.

ATT&CK Techniques

Execution
9 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Volexity InkySquid BLUELIGHT August 2021 — Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.
  2. CrowdStrike Richochet Chollima September 2021 — CrowdStrike. (2021, September 30). Adversary Profile - Ricochet Chollima. Retrieved September 30, 2021.
  3. FireEye APT37 Feb 2018 — FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.
  4. Securelist ScarCruft May 2019 — GReAT. (2019, May 13). ScarCruft continues to evolve, introduces Bluetooth harvester. Retrieved June 4, 2019.
  5. Talos Group123 — Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.
  6. Securelist ScarCruft Jun 2016 — Raiu, C., and Ivanov, A. (2016, June 17). Operation Daybreak. Retrieved February 15, 2018.

Intel Summary

29

Techniques

24

Tools

9

Campaigns

0

IOCs

0

Observed Data

10

Tactics

Tags

APT
espionage
cyber espionage
government
critical infrastructure

Details

MITRE ID
G0067
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
North Korea (KP)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--4a2ce82e-1a74-468a-a6fb-bbead541383c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.