Threat intelligence
- Suspected origin
- North Korea
- First seen
- 2012-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Aerospace, Automotive, Chemical, Education, Financial, Government, Healthcare, High-Tech, Manufacturing, Media, Technology, Transportation
- TLP
- WHITE
Some research organizations link this group to Lazarus Group, Hidden Cobra, Labyrinth Chollima.
(FireEye) Read our report, APT37 (Reaper): The Overlooked North Korean Actor, to learn more about our assessment that this threat actor is working on behalf of the North Korean government, as well as various other details about their operations:
• Targeting: Primarily South Korea – though also Japan, Vietnam and the Middle East – in various industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare.
• Initial Infection Tactics: Social engineering tactics tailored specifically to desired targets, strategic web compromises typical of targeted cyberespionage operations, and the use of torrent file-sharing sites to distribute malware more indiscriminately.
• Exploited Vulnerabilities: Frequent exploitation of vulnerabilities in Hangul Word Processor (HWP), as well as Adobe Flash. The group has demonstrated access to zero-day vulnerabilities (CVE-2018-0802), and the ability to incorporate them into operations.
• Command and Control Infrastructure: Compromised servers, messaging platforms, and cloud service providers to avoid detection. The group has shown increasing sophistication by improving their operational security over time.
• Malware: A diverse suite of malware for initial intrusion and exfiltration. Along with custom malware used for espionage purposes, APT37 also has access to destructive malware.
Also known as
APT 37APT37ATK 4CeriumCrooked PiscesG0067Geumseong121Group 123Group123HermitInkySquidITG10Moldy PiscesOpal SleetOsmiumReaperRed EyesRicochet ChollimaRuby SleetScarCruftTA-RedAntTEMP.ReaperVenus 121
Vulnerabilities exploited
Tooling and malware
BLUELIGHTCobalt StrikeCORALDECKDOGCALLFinal1stspyHAPPYWORKKARAENavRATPOORAIMROKRATSHUTTERSPEEDSLOWDRIFTWINERACK
MITRE ATT&CK techniques
T1005 Data from Local SystemT1123 Audio CaptureT1105 Ingress Tool TransferT1033 System Owner/User DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1120 Peripheral Device DiscoveryT1059 Command and Scripting InterpreterT1106 Native APIT1203 Exploitation for Client ExecutionT1529 System Shutdown/RebootT1189 Drive-by CompromiseT1027 Obfuscated Files or InformationT1055 Process Injection
Coverage 4
threat-intel
North Korean-aligned threat actors are deploying a sophisticated Linux espionage toolkit targeting automotive and media organizations in South Korea. The toolkit, incorporating a custom HAProxy plugin and various trojani…
threat-intel
A previously undocumented Linux toolkit, dubbed ‘ted,’ has been discovered embedded within trojanized HAProxy load balancers used by two South Korean organizations. Developed by North Korean state-sponsored actors (likel…

threat-intel
North Korean APT37 group utilized a spear-phishing campaign mimicking Microsoft security alerts to deploy NarwhalRAT malware. The campaign leveraged urgency and confusion to trick victims into executing a malicious LNK f…

threat-intel
A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a…