THREATOPS Actor Dossier
LIVE ← Dashboard

APT37

G00672 reports
aliases · APT37 · InkySquid · ScarCruft · Reaper · Group123 · TEMP.Reaper · Ricochet Chollima
Export dossier:
2
Reports
12
Techniques
10
Tactics
2
Countries
23%
Hunt coverage
7
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1132.001 (Standard Encoding), T1556.003 (Pluggable Authentication Modules), T1059.007 (JavaScript).
  • Primary targeting: KP, KR.
  • Resurgent after a quiet period: 1 report(s) in last 30d vs 0 prior (+100%).
  • Recent movement: 35 new technique(s), 31 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 23% of 35 observed techniques (27 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

ResurgentLast 30d: 1 vs 0 prior (+100%)· first reported 2026-05-05 · last 2026-09-04
0
7d
1
30d
1
90d
2
All
0.1
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
T1132.001T1556.003T1059.007T1543T1539T1036.005T1497.001T1588.006T1119T1082T1071T1106
Targeting gained
KPKR
New infrastructure
4bb923eb040aa13ca8fd409c31ee4729c60ddff35db1b6d52faf60b4f32d6fd0c7c938e4d05d29a109739441ed4599bac2f8159028f772f71e4b25c8fea1bc36632c71e5a839803469ef60ac47595d36feeea9d0bf6ae7396d28271baa51ae50df5169ce8f30b57928934ae67478d0e690c91d046e35a63872e70936f0dbe459142a1d867617c35f8d0cce5da8bfab4de81a1acb04aacdf757346946b0f5e30f83f7d565b0465546027052b597af46eae3a199e77007a78d50a993cb174c685eba96eb442c9507e36cf1b5e92a9c0756f597a5ddefb38eba32961c52ed72f4cd8d467b5c5d95ae6aeca4aaeea14d7956

Overview

Analyst triage
Intelligence summary

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123)

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected