Skip to main content
Mallory
🇰🇵 KP4 malware familiesExploits CVEs in the wild

TA-RedAnt

Also known asTA-RedAnt

TA-RedAnt is a North Korean-linked threat actor identified in the provided content as APT37. The reporting describes the group conducting espionage-focused operations primarily against South Korean and North Korea-related targets, including North Korea-related professionals in South Korea, national security think tanks, academia and research personnel, and previously North Korean defectors and South Korean experts on North Korea. The content also describes broader targeting of South Korean users through a large-scale campaign. Observed activity includes spear-phishing, watering-hole-style delivery, abuse of trusted cloud services, and exploitation of Internet Explorer vulnerabilities. In May 2024, TA-RedAnt/APT37 was attributed with “Operation Code on Toast,” a large-scale campaign that exploited CVE-2024-38178, a previously unknown Internet Explorer Chakra engine vulnerability, via malicious toast advertisements delivered through free software widely used in South Korea. According to the content, the attackers compromised a domestic ad agency server, injected a malicious iframe into HTML served to the ad program, achieved remote code execution, used a multi-stage malware chain with first-stage malware injected into explorer.exe, collected host information in a second stage, and ultimately deployed a RokRAT variant for command execution and data theft. The RokRAT variant used cloud services for C2, with Yandex Cloud configured by default. The content also states that in March 2025 TA-RedAnt distributed RokRAT through an LNK-based spear-phishing campaign themed as an academic event associated with a South Korean security think tank. That activity reportedly used ZIP/LNK delivery, Dropbox, and “Living off Trusted Sites” cloud-service-based C2, and is listed as exploiting CVE-2022-41128. The group is described as using multiple delivery strategies including watering hole, spear phishing, and SNS phishing, and as targeting Windows as well as Android users with malicious APKs and macOS users. In June 2025, TA-RedAnt reportedly targeted South Korea-based North Korea-related professionals in international relations, political science, academia, and research using the Rustonotto and Chinotto backdoors together with the FadeStealer data theft tool. Reported execution chains included LNK to PowerShell, CHM to HTA/PowerShell, and downloading and executing remote CAB/RAR files. Rustonotto is described as a Rust-compiled HTTP backdoor using Base64-encoded commands and responses. Chinotto is described as a PowerShell backdoor supporting file transfer, command execution, and persistence via registry and scheduled tasks. FadeStealer is described as collecting data through keylogging, screenshots, audio recording, device and file collection, and exfiltration of sensitive data. The content further states that TA-RedAnt used TxF-based process doppelgänging for concealed execution and used scheduler and registry mechanisms for persistence, with a single PHP-based C2 structure integrating Chinotto, FadeStealer, and Rustonotto. The provided reporting also attributes to TA-RedAnt/APT37 direct targeting of air-gapped environments. In that activity, the group combined LNK-based initial compromise, Zoho WorkDrive-based command-and-control, Ruby runtime droppers, and removable media such as USB for command delivery and data exfiltration. The campaign is described as enabling persistent reconnaissance, keylogging, and audio and video collection inside isolated networks. Known aliases directly supported by the content: TA-RedAnt, APT37.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
  • Media & Entertainment
  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇰🇷 South Korea

Where they're from

Attributed origin per open-source reporting.

  • KP
MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics18 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1091
Replication Through Removable Media
T1189
Drive-by Compromise
TA0002
Execution
3 techniques
T1059×2
Command and Scripting Interpreter
T1203
Exploitation for Client Execution
T1204
User Execution
T1204.002×2
Malicious File
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
T1547.009
Shortcut Modification
TA0004
Privilege Escalation
2 techniques
T1055
Process Injection
T1547
Boot or Logon Autostart Execution
T1547.009
Shortcut Modification
TA0005
Stealth
1 technique
T1055
Process Injection
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1091
Replication Through Removable Media
TA0011
Command and Control
2 techniques
T1071×2
Application Layer Protocol
T1105
Ingress Tool Transfer
TA0010
Exfiltration
2 techniques
T1041
Exfiltration Over C2 Channel
T1052
Exfiltration Over Physical Medium
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

TA-RedAnt | Mallory