APT37 is a North Korea-linked espionage threat actor known for sustained operations primarily targeting South Korean government, policy, academic, media, defense, and North Korea-related communities, while also conducting broader intelligence collection against regional and international targets. Widely used aliases include ScarCruft, Reaper, Ricochet Chollima, InkySquid, Group123, TA-RedAnt, and TEMP.Reaper. The group is closely associated with the RokRAT malware family and has repeatedly abused legitimate cloud and web services for command-and-control and exfiltration, including platforms such as Dropbox, pCloud, Yandex Cloud, and Zoho WorkDrive. Reported malware and tooling linked to the actor include RokRAT, RoKRAT, NarwhalRAT, Rustonotto, Chinotto, FadeStealer, and BirdCall. Campaigns attributed or assessed as highly likely linked to the group include Operation Artemis and Operation Capsule Vault. APT37 frequently relies on targeted social engineering and spear-phishing, often using topical or credible lures tied to academic events, policy themes, security notices, military subjects, or trusted public figures. Delivery mechanisms observed across campaigns include malicious shortcut files, ISO images, disguised executables, HWP and HWPX documents with embedded OLE content, and trojanized legitimate software installers. The actor commonly displays decoy content to reduce suspicion while executing malware in parallel. Tradecraft associated with APT37 includes multistage loaders, shellcode restoration in memory, XOR-based payload decryption, DLL sideloading, process injection into legitimate Windows processes, and fileless or memory-resident execution. The group has used persistence mechanisms such as Registry Run keys and scheduled tasks. It also performs extensive host reconnaissance, including collection of operating system and BIOS-derived identifiers, drive enumeration, process discovery, and peripheral discovery such as Bluetooth device harvesting. In some operations, the actor has directly targeted air-gapped environments by combining LNK-based initial compromise, removable-media workflows, Ruby runtime droppers, and cloud-backed command relays to bypass network separation. Post-compromise capabilities attributed to APT37 include remote command execution, screenshot capture, keylogging, microphone recording, document theft, collection from removable media, and staged upload of stolen data. The actor has shown particular interest in Korean-language document formats and victim environments associated with South Korea. Its operations consistently reflect long-term intelligence collection objectives aligned with North Korean state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
Scarcruft ... Attack using Flash Zero Day (CVE-2016-4171, CVE-2018-4878)
ScarCruft exploits CVE-2020-1380 to compromise victims.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878)...
...used exploits for... Word (CVE-2017-0199)...
10 more CVEs tied to this actor tracked in Mallory.
306 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Assessed as highly likely responsible for Operation Capsule Vault, a spear-phishing campaign delivering a RokRAT variant against people in research, policy, and academic fields using Dropbox-hosted ISO files and a disguised PIF payload for in-memory execution and cloud-based C2.
Referenced as the threat actor associated with BirdCall malware in a post linking to an analysis of malware masquerading as Zangi Messenger.
Used NarwhalRAT for surveillance and information theft, including keylogging, screen capture, and microphone recording.
Likely connected to Operation Capsule Vault, a targeted spear-phishing campaign using real academic event materials to deliver a RokRAT variant via a cloud-hosted ISO image and a document-disguised executable.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.