APT-C-37, also referred to in the provided content as Pat-Bear, is a threat actor mentioned in reporting as having used the Android remote access trojan SpyNote in its operations. The content specifically associates APT-C-37 (Pat-Bear) with SpyNote alongside other groups such as OilRig (APT34), Kimsuky, and OilAlpha. It also notes that Arabic-named LNK files disguised as government forms are a documented TTP used by APT-C-37 (Pat-Bear). Based on the provided material, APT-C-37 has been linked to use of SpyNote/SpyMax/CypherRat, an Android RAT commonly delivered as trojanized APKs via social engineering. SpyNote capabilities described in the content include abuse of Android Accessibility Services, progressive permission escalation, persistence via BroadcastReceiver components, and persistent TCP-based command-and-control communications. The malware can collect location data, contacts, SMS, call history, files, device information, and credentials; enable keylogging; monitor screens; and access microphone and camera functions. The content also states that SpyNote-based campaigns have targeted government agencies, NGOs, media organizations, financial institutions, activists, and high-value assets, but it does not attribute those target sets exclusively to APT-C-37. No higher-confidence attribution details such as country sponsorship, organizational structure, or distinct sub-groups for APT-C-37 are provided in the content beyond the alias Pat-Bear and the reported use of SpyNote and Arabic-themed LNK lures.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of a known actor associated with Arabic-language lure documents disguised as government forms in targeted campaigns.
Explicitly cited as a threat actor that has included SpyNote in its tooling portfolio during operations against high-value targets.
Explicitly identified as a group that has leveraged SpyNote in malicious campaigns against critical sectors and individuals.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.