APT37 is a North Korea-linked state-sponsored cyber espionage group active primarily against South Korean targets, while also targeting organizations and individuals of broader strategic interest. Widely tracked under aliases including ScarCruft, Reaper, Ricochet Chollima, InkySquid, TA-RedAnt, Group123, and TEMP.Reaper, the group is associated with intelligence collection operations focused on government, defense, policy, academic, research, media, and North Korea-related communities. APT37 is known for sustained spear-phishing and social-engineering campaigns that use highly tailored lures, including academic events, security notices, and politically relevant themes. The group has repeatedly targeted South Korean users and professionals with document-themed malware delivery, malicious shortcut files, disguised executables, and archive or disk-image based infection chains. Reported operations have also used social platforms and messaging applications to build rapport with targets before delivering malware. The group is strongly associated with the RokRAT malware family and related tooling, as well as campaigns involving NarwhalRAT, BirdCall, Rustonotto, Chinotto, FadeStealer, and RoKRAT variants. Its malware commonly performs host reconnaissance, document theft, screen capture, command execution, keylogging, microphone recording, and broader remote-control functions. APT37 has also demonstrated interest in removable media and air-gapped or network-separated environments, including use of LNK-based initial compromise, USB-mediated command delivery and exfiltration, and cloud-backed command-and-control patterns intended to bypass segmentation. A defining characteristic of APT37 tradecraft is abuse of legitimate cloud and web services for command and control, staging, and exfiltration. Public reporting has linked the group to use of services such as Dropbox, pCloud, Yandex Cloud, and Zoho WorkDrive, enabling blending with normal traffic and resilient multi-channel C2. The group has also used memory-resident loaders, shellcode stages, process injection into legitimate processes, decoy documents, and persistence mechanisms such as Registry Run keys and scheduled tasks. Recent reporting has tied APT37 to campaigns such as Operation Capsule Vault, in which a RokRAT variant was delivered through spear-phishing aimed at research, policy, and academic personnel using a real conference lure and a multistage in-memory loader. Other reported activity includes targeting North Korea-related professionals in South Korea with Rustonotto, Chinotto, and FadeStealer; use of NarwhalRAT for surveillance and collection; and operations abusing legitimate software themes and cloud APIs for stealthy post-compromise control. APT37 has also been publicly linked to exploitation of Microsoft and browser vulnerabilities, including reported use of a Windows zero-day in 2024 against South Korean users via malicious advertising, although some such exploit attributions remain uncorroborated in public reporting. Overall, APT37 is best characterized as a persistent DPRK espionage actor that combines tailored social engineering, malware innovation, cloud-service abuse, and stealthy post-exploitation techniques to collect intelligence from South Korean and related strategic targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
Scarcruft ... Attack using Flash Zero Day (CVE-2016-4171, CVE-2018-4878)
ScarCruft exploits CVE-2020-1380 to compromise victims.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878)...
...used exploits for... Word (CVE-2017-0199)...
10 more CVEs tied to this actor tracked in Mallory.
306 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Assessed as highly likely responsible for Operation Capsule Vault, a spear-phishing campaign delivering a RokRAT variant against people in research, policy, and academic fields using Dropbox-hosted ISO files and a disguised PIF payload for in-memory execution and cloud-based C2.
Referenced as the threat actor associated with BirdCall malware in a post linking to an analysis of malware masquerading as Zangi Messenger.
Used NarwhalRAT for surveillance and information theft, including keylogging, screen capture, and microphone recording.
Likely connected to Operation Capsule Vault, a targeted spear-phishing campaign using real academic event materials to deliver a RokRAT variant via a cloud-hosted ISO image and a document-disguised executable.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.