Also known as: InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, Group 123, Red Eyes, APT37, Venus 121 (금성121), APT 37, Operation Daybreak, Operation Erebus, Reaper Group, Venus 121, ATK4, G0067, Moldy Pisces, APT-C-28, PLAIN NEPTUNE
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Reaper; Erebus; Golden Time; Evil New Year; Are you Happy?; FreeMilk; North Korean Human Rights; Evil New Year 2018
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT37 is a North Korean state-sponsored cyber espionage group active since at least 2012. Known for its sophisticated campaigns targeting South Korea and other countries across Asia and the Middle East, APT37 employs a wide range of tactics to steal sensitive information. The group has demonstrated a particular focus on healthcare, aerospace, government, and critical infrastructure sectors.
Goals & Targeting
APT37's strategic objectives revolve around conducting cyber espionage targeting sectors such as healthcare, aerospace & defense, manufacturing, government, and critical infrastructure. The group focuses on countries with significant political or economic interests opposing North Korea, including South Korea, Japan, India, Russia, and Middle Eastern nations. Their campaigns often involve large-scale operations aimed at stealing sensitive information and disrupting the targeted organizations.
Enhanced Description
APT37, also known as InkySquid or TEMP.Reaper, is a North Korean state-sponsored cyber espionage group that has been operational since at least 2012. The group has conducted numerous campaigns between 2016-2018, including Operation Daybreak, Golden Time, and Evil New Year. APT37 primarily targets South Korea but has also targeted other countries such as Japan, India, Russia, Nepal, China, Romania, and Kuwait. Their main objective is to gather intelligence through cyber espionage activities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT37 has been involved in multiple campaigns, including Operation Daybreak and Operation Erebus. These campaigns often involve large-scale spear-phishing attacks, the deployment of custom malware, and the targeting of critical infrastructure sectors. The group's operational tempo is consistent with other North Korean state-sponsored actors, with a focus on long-term espionage objectives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the description of APT37 as a North Korean state-sponsored group, based on multiple sources and campaigns. However, some uncertainty exists regarding specific tools and techniques due to potential overlaps with other North Korean-affiliated groups.
Reaper
Erebus
Golden Time
Evil New Year
Are you Happy?
FreeMilk
North Korean Human Rights
Evil New Year 2018
Daybreak
No observed data linked yet.
No IOCs linked yet.
29
Techniques
24
Tools
9
Campaigns
0
IOCs
0
Observed Data
10
Tactics