APT37

MITRE ATT&CK: G0067 View on attack.mitre.org

Aliases: InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, APT 37, Group 123, Operation Daybreak, Operation Erebus, Reaper Group, Red Eyes, Venus 121, ATK4, Moldy Pisces, APT-C-28, APT37

First seen
2012-01-01 00:00:00
Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
383 (258 malicious)
Last IoC activity
2026-09-02 00:39:32
Profile updated
2026-07-07 12:32:07

Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp country_code:vn country_code:ru country_code:np country_code:cn country_code:in country_code:ro country_code:kw

Context

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Recent IoC activity

258 malicious indicators in Maltiverse are attributed to APT37 (G0067). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.mycurrency.net 2026-09-03 2
hostname camaralastro.pb.gov.br 2026-09-03 2
hostname sweetmonsterr.com 2026-09-03 4
hostname pakhams.com 2026-09-02 2
hostname essayever.com 2026-09-02 3
hostname ticket.ipv10.eu 2026-09-02 1
hostname autopartslife.com 2026-09-02 2
hostname indomobilhino.co.id 2026-09-02 2
hostname draleccheng.ca 2026-09-02 4
hostname devlancetech.com 2026-09-02 2
hostname market-egypt.com 2026-09-02 2
hostname azskk.com 2026-09-02 1
hostname featherincap.com 2026-09-02 2
hostname gopackapp.com 2026-09-02 2
hostname cyberchef.net 2026-09-02 1
hostname dialog.gg 2026-09-02 1
hostname booking.msg.bluhotels.com 2026-09-02 1
hostname abu.usaday.biz 2026-09-02 2
hostname koaagj.co.kr 2026-09-02 1
hostname ri-guard.com 2026-09-02 1

Detection coverage

  • 155 YARA rules
  • 649 Sigma rules

Malware & tools used

  • Registry Run Keys / Startup Folder (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Python (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)
  • Steganography (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Invalid Code Signature (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Data from Local System (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • Native API (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Process Injection (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Process Discovery (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Spearphishing Attachment (attack-pattern)

Exploited vulnerabilities

  • CVE-2016-4171 (vulnerability)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • volexity.com — North Korean Apt Inkysquid Infects Victims Using Browser Exploits (report)
  • Mandiant — Apt37 Overlooked North Korean Actor (report)
  • Mandiant — Rpt Apt37 (report)
  • Cisco Talos — Korea In Crosshairs (report)
  • twitter.com — 966126706107953152 (report)
  • cfr.org — Apt 37 (report)
  • bleepingcomputer.com — Report Ties North Korean Attacks To New Malware Linked By Word Macros (report)
  • Palo Alto Unit 42 — Unit42 Freemilk Highly Targeted Spear Phishing Campaign (report)
  • Cisco Talos — Korea In Crosshairs (report)
  • MITRE ATT&CK — G0067 (report)
  • Kaspersky — 75082 (report)
  • Kaspersky — 75100 (report)
  • Kaspersky — 90729 (report)
  • threatpost.com — 118642 (report)
  • Palo Alto Unit 42 — Moldypisces (report)
  • services.google.com — Apt37 Reaper The Overlooked North Korean Actor (report)
  • CrowdStrike — Ricochet Chollima (report)

External references