CORALDECK

MITRE ATT&CK: S0212 View on attack.mitre.org

Aliases: CORALDECK

First seen
2020-07-15 00:00:00
Malware type
spyware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:21:43

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr

Context

CORALDECK is an exfiltration tool used by the North Korean threat actor APT37. It is primarily employed to steal sensitive information from targeted systems, focusing mainly on governmental and telecommunications sectors in South Korea.

Detection coverage

  • 43 Sigma rules

Malware & tools used

  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Archive via Utility (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Reports & references

  • services.google.com — Apt37 Reaper The Overlooked North Korean Actor (report)
  • MITRE ATT&CK — S0212 (report)

External references