APT37
MITRE ATT&CK: G0067 View on attack.mitre.org
Aliases: InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, APT 37, Group 123, Operation Daybreak, Operation Erebus, Reaper Group, Red Eyes, Venus 121, ATK4, Moldy Pisces, APT-C-28, APT37
- First seen
- 2012-01-01 00:00:00
- Origin
- KP
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 383 (258 malicious)
- Last IoC activity
- 2026-09-02 00:39:32
- Profile updated
- 2026-07-07 12:32:07
Targeted industries: government-and-public-sector media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:kr country_code:jp country_code:vn country_code:ru country_code:np country_code:cn country_code:in country_code:ro country_code:kw
Context
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Recent IoC activity
258 malicious indicators in Maltiverse are attributed to APT37 (G0067). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | www.mycurrency.net | 2026-09-03 | 2 |
| hostname | camaralastro.pb.gov.br | 2026-09-03 | 2 |
| hostname | sweetmonsterr.com | 2026-09-03 | 4 |
| hostname | pakhams.com | 2026-09-02 | 2 |
| hostname | essayever.com | 2026-09-02 | 3 |
| hostname | ticket.ipv10.eu | 2026-09-02 | 1 |
| hostname | autopartslife.com | 2026-09-02 | 2 |
| hostname | indomobilhino.co.id | 2026-09-02 | 2 |
| hostname | draleccheng.ca | 2026-09-02 | 4 |
| hostname | devlancetech.com | 2026-09-02 | 2 |
| hostname | market-egypt.com | 2026-09-02 | 2 |
| hostname | azskk.com | 2026-09-02 | 1 |
| hostname | featherincap.com | 2026-09-02 | 2 |
| hostname | gopackapp.com | 2026-09-02 | 2 |
| hostname | cyberchef.net | 2026-09-02 | 1 |
| hostname | dialog.gg | 2026-09-02 | 1 |
| hostname | booking.msg.bluhotels.com | 2026-09-02 | 1 |
| hostname | abu.usaday.biz | 2026-09-02 | 2 |
| hostname | koaagj.co.kr | 2026-09-02 | 1 |
| hostname | ri-guard.com | 2026-09-02 | 1 |
Detection coverage
- 155 YARA rules
- 649 Sigma rules
Malware & tools used
- Registry Run Keys / Startup Folder (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Python (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- Steganography (attack-pattern)
- Bidirectional Communication (attack-pattern)
- System Information Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Invalid Code Signature (attack-pattern)
- Bypass User Account Control (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Data from Local System (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- Native API (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Process Injection (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Process Discovery (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Windows Command Shell (attack-pattern)
- Spearphishing Attachment (attack-pattern)
Exploited vulnerabilities
- CVE-2016-4171 (vulnerability)
Related threat objects
- Lazarus Group (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- volexity.com — North Korean Apt Inkysquid Infects Victims Using Browser Exploits (report)
- Mandiant — Apt37 Overlooked North Korean Actor (report)
- Mandiant — Rpt Apt37 (report)
- Cisco Talos — Korea In Crosshairs (report)
- twitter.com — 966126706107953152 (report)
- cfr.org — Apt 37 (report)
- bleepingcomputer.com — Report Ties North Korean Attacks To New Malware Linked By Word Macros (report)
- Palo Alto Unit 42 — Unit42 Freemilk Highly Targeted Spear Phishing Campaign (report)
- Cisco Talos — Korea In Crosshairs (report)
- MITRE ATT&CK — G0067 (report)
- Kaspersky — 75082 (report)
- Kaspersky — 75100 (report)
- Kaspersky — 90729 (report)
- threatpost.com — 118642 (report)
- Palo Alto Unit 42 — Moldypisces (report)
- services.google.com — Apt37 Reaper The Overlooked North Korean Actor (report)
- CrowdStrike — Ricochet Chollima (report)
External references
- mitre-attack — G0067
- Ricochet Chollima
- APT37
- Reaper
- Group123
- TEMP.Reaper
- ScarCruft
- InkySquid
- Volexity InkySquid BLUELIGHT August 2021
- CrowdStrike Richochet Chollima September 2021
- FireEye APT37 Feb 2018
- Securelist ScarCruft May 2019
- Talos Group123
- Securelist ScarCruft Jun 2016
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy