ESET reported that ScarCruft—also tracked as APT37 or Reaper—used a previously undocumented Windows backdoor called Dolphin in intrusions targeting South Korea, including a 2021 watering-hole attack against a South Korean online newspaper. The malware was delivered as a selective second-stage payload through a multistage loader chain that used a downloaded Python 2.7 interpreter, XOR-encrypted shellcode, process injection, and persistence via Run registry keys and a scheduled task.
Dolphin used Google Drive for command-and-control and data exfiltration and supported file theft from fixed, removable, and portable drives, keylogging, screenshots, shell command and shellcode execution, and browser credential theft. ESET said earlier variants also altered victims’ signed-in Google and Gmail security settings to maintain inbox access through IMAP and less secure app access, while later versions added evasion features such as dynamic API resolution and string obfuscation and temporarily removed credential-stealing functions; the activity was observed from April 2021 through January 2022 and attributed to the North Korea-aligned espionage group’s long-running focus on South Korean and other regional targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
ESET published analysis of Dolphin on November 30, 2022, describing it as a previously unreported ScarCruft backdoor that used Google Drive for command-and-control and exfiltration. The report linked the malware to ScarCruft/APT37 and detailed its espionage-focused capabilities against South Korean targets.
From April 2021 through January 2022, ESET observed several Dolphin variants with feature additions and evasion changes, including dynamic API resolution, string obfuscation, and temporary removal of credential-stealing capabilities. Earlier versions also altered Google and Gmail security settings to help preserve access to victims' email accounts.
In 2021, ScarCruft used Dolphin in a watering-hole attack targeting visitors to a South Korean online newspaper. The operation delivered the backdoor through a multistage loader chain involving Python, encrypted shellcode, process injection, and persistence mechanisms.
ESET observed ScarCruft deploying multiple versions of the previously unreported Dolphin backdoor starting in April 2021. The malware was used as a selective second-stage payload after initial compromise and showed ongoing development over time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.