Researchers reported that APT37/Reaper (also tracked as ScarCruft) ran a surveillance campaign against North Korean defectors in South Korea and human rights activists, using credential-harvesting phishing pages and malware-laced lures to collect intelligence. The operation impersonated services including Naver, iCloud, Kakao, Mail.ru, and 163.com, and some phishing pages were built to intercept credentials and evade or relay two-factor authentication flows through web-based communications channels.
Investigators found two exposed Reaper command-and-control servers that revealed both hosted malware and stolen victim data, providing a detailed view of the intrusion set. The campaign used CHM files for initial infection, PowerShell backdoors, modified DLL loaders, ExtremeVNC, and multiple Chinotto malware variants, including new Windows DLL samples identified as CKU and DATA, as well as an AblyGo backdoor, indicating ongoing tool development in a sustained North Korea-linked cyberespionage effort.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Cyble published analysis of a Chinotto Android spyware sample attributed to APT37/Reaper that masqueraded as a SecureTalk app and stole contacts, SMS messages, call logs, account details, device information, and files. The report linked the malware to command-and-control infrastructure at haeundaejugong[.]com and framed the activity as targeting North Korean defectors and human rights activists.
SEKOIA.IO found infection vectors in a GitHub repository that had been online since 2021 and used by Reaper as staging infrastructure. The repository hosted archives containing malicious CHM-based lures and related payload delivery material.
SEKOIA.IO noted that Chinotto malware had previously been documented by Kaspersky in 2021 and attributed to Reaper. This established prior public reporting on the malware family later seen in newer variants.
SEKOIA.IO stated that Reaper, also known as APT37, has been active since at least 2012 as a North Korea-nexus intrusion set. The group primarily conducts cyberespionage against NGOs, civil society, dissidents, journalists, and North Korean defectors.
SEKOIA.IO identified new Chinotto Windows DLL variants that it named CKU and DATA. Unlike older Chinotto DLLs that requested commands over HTTP, these newer variants used hardcoded commands and mainly communicated to exfiltrate collected data.
SEKOIA.IO recovered RAR and ZIP infection vectors containing malicious Microsoft Compressed HTML files, sometimes paired with decoy password-protected benign documents. When opened, the CHM files executed MSHTA to download and launch a lighter Chinotto PowerShell backdoor.
The exposed infrastructure contained credential-harvesting phishing pages impersonating services including Naver, iCloud, Kakao, Mail.ru, and 163.com. One workflow targeting iCloud, Naver, and Kakao used HTTP, WebSockets, Ably, and PubNub to help bypass two-factor authentication.
SEKOIA.IO discovered two open command-and-control servers belonging to Reaper that exposed hosted malware and exfiltrated victim data. Based on the infrastructure and tooling, the company assessed with high confidence that the activity was associated with Reaper and almost certainly related to surveillance of North Korean defectors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 262 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourcesecurelist.com
Open sourceblog.cyble.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.