news.mlab.sh
Threat intelligence
Threat actor

Reaper

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
North Korea
First seen
2012-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aerospace, Automotive, Chemical, Education, Financial, Government, Healthcare, High-Tech, Manufacturing, Media, Technology, Transportation
TLP
WHITE

Some research organizations link this group to Lazarus Group, Hidden Cobra, Labyrinth Chollima. (FireEye) Read our report, APT37 (Reaper): The Overlooked North Korean Actor, to learn more about our assessment that this threat actor is working on behalf of the North Korean government, as well as various other details about their operations: • Targeting: Primarily South Korea – though also Japan, Vietnam and the Middle East – in various industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare. • Initial Infection Tactics: Social engineering tactics tailored specifically to desired targets, strategic web compromises typical of targeted cyberespionage operations, and the use of torrent file-sharing sites to distribute malware more indiscriminately. • Exploited Vulnerabilities: Frequent exploitation of vulnerabilities in Hangul Word Processor (HWP), as well as Adobe Flash. The group has demonstrated access to zero-day vulnerabilities (CVE-2018-0802), and the ability to incorporate them into operations. • Command and Control Infrastructure: Compromised servers, messaging platforms, and cloud service providers to avoid detection. The group has shown increasing sophistication by improving their operational security over time. • Malware: A diverse suite of malware for initial intrusion and exfiltration. Along with custom malware used for espionage purposes, APT37 also has access to destructive malware.

Also known as

APT 37APT37ATK 4CeriumCrooked PiscesG0067Geumseong121Group 123Group123HermitInkySquidITG10Moldy PiscesOpal SleetOsmiumReaperRed EyesRicochet ChollimaRuby SleetScarCruftTA-RedAntTEMP.ReaperVenus 121

Vulnerabilities exploited

Tooling and malware

BLUELIGHTCobalt StrikeCORALDECKDOGCALLFinal1stspyHAPPYWORKKARAENavRATPOORAIMROKRATSHUTTERSPEEDSLOWDRIFTWINERACK

MITRE ATT&CK techniques

T1005 Data from Local SystemT1123 Audio CaptureT1105 Ingress Tool TransferT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1120 Peripheral Device DiscoveryT1059 Command and Scripting InterpreterT1106 Native APIT1203 Exploitation for Client ExecutionT1529 System Shutdown/RebootT1189 Drive-by CompromiseT1027 Obfuscated Files or InformationT1055 Process Injection

Coverage 4