APT37, also known as Earth Manticore, is a North Korean state-sponsored threat actor associated with cyber espionage operations. The group has been observed using crafted Windows shortcut files to conceal malicious command-line execution from users, including oversized .lnk files padded with large amounts of whitespace and junk content to evade detection and obscure malicious behavior in the Windows user interface. This tradecraft aligns with broader North Korean intrusion activity focused on stealthy delivery and information theft. APT37 has been linked to exploitation of a Windows .lnk user-interface misrepresentation flaw tracked as ZDI-CAN-25373 / ZDI-25-148. In these operations, the actor used manipulated shortcut metadata and hidden command-line arguments to disguise malicious execution while presenting benign-looking files to victims. The technique supports covert payload delivery and defense evasion by reducing the likelihood that users or defenders will recognize the true behavior of the shortcut. Available reporting in this context supports North Korean attribution and indicates that campaigns using this technique were primarily associated with espionage and data theft. The broader victim set tied to this exploitation activity included organizations in government, finance, telecommunications, military and defense, energy, and think tanks and NGOs across multiple regions. Earth Manticore is also known by the alias APT37.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korean espionage-oriented threat actor observed exploiting ZDI-CAN-25373 via crafted .lnk files padded with large amounts of whitespace and junk content to evade detection.
Earth Manticore is a North Korean state-sponsored APT group known for using large, padded .lnk files to exploit ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.