APT37

πŸ”΄ High
Also known as: APT 37, APT-C-28, APT37, APT37(ReaperοΌ‰, ATK4, G0067, Group 123, Group123, InkySquid, Moldy Pisces, Operation Daybreak, Operation Erebus, Reaper, Reaper Group, Red Eyes, Ricochet Chollima, ScarCruft, ScarCruft - APT-C-28, TEMP.Reaper, Venus 121

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. FireEye APT37 Feb 2018 Securelist ScarCruft Jun 2016 Talos Group123

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

🌍 Country North Korea
πŸ“… Activity 2016 β€” 2023
⚑ Risk Level High
🧭 ATT&CK G0067
Government Private sector
2016
2023

Introduction

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. FireEye APT37 Feb 2018 Securelist ScarCruft Jun 2016 Talos Group123 North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Activities and Tactics

Targeted Sectors: Government, Private sector

Country of Origin: πŸ‡°πŸ‡΅ North Korea

Risk Level: High

First Seen: 2016

Last Activity: 2023

Suspected Victims: South Korea, Japan, Vietnam

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 3 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • SPACESHIP

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: North Korea Additional attribution information pending cataloguing.

References

[1] mitre-attack [9] Volexity InkySquid BLUELIGHT August 2021 Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021. [10] CrowdStrike Richochet Chollima September 2021 CrowdStrike. (2021, September 30). Adversary Profile - Ricochet Chollima. Retrieved September 30, 2021. [11] FireEye APT37 Feb 2018 FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024. [12] Securelist ScarCruft May 2019 GReAT. (2019, May 13). ScarCruft continues to evolve, introduces Bluetooth harvester. Retrieved June 4, 2019. [13] Talos Group123 Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018. [14] Securelist ScarCruft Jun 2016 Raiu, C., and Ivanov, A. (2016, June 17). Operation Daybreak. Retrieved February 15, 2018.