APT-C-37
APT-C-37, also known as Pat-Bear, is a threat actor referenced in reporting as having used the SpyNote Android remote administration tool in prior campaigns. Reported SpyNote-based activity associated with groups including APT-C-37 has targeted government agencies, NGOs, media organizations, financial institutions, and activists. In the provided reporting, APT-C-37 is also specifically noted for using Arabic-named LNK files disguised as government forms as a documented TTP. The cited SpyNote tradecraft includes delivery via WhatsApp in targeted attacks, use of obfuscated Android payloads, concealment after installation, background execution, collection of location data, contacts, SMS, call information, device details, files, screenshots, and keystrokes, and abuse of Android accessibility permissions to monitor on-screen activity and hinder app removal. Known alias in the provided content: Pat-Bear.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Non-Governmental Organizations
- Independent Media
- Financial Services
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of a known actor associated with Arabic-language lure documents disguised as government forms in targeted campaigns.
Explicitly identified as a group that has leveraged SpyNote in malicious campaigns against critical sectors and individuals.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.