APT37

G0067

Threat group.View on attack.mitre.org

About this group

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Techniques used29

Procedure examples29

TechniqueProcedure example
T1005
Data from Local System

APT37 has collected data from victims' local systems.

T1027
Obfuscated Files or Information

APT37 obfuscates strings and payloads.

T1027.003
Steganography

APT37 uses steganography to send images to users that are embedded with shellcode.

T1033
System Owner/User Discovery

APT37 identifies the victim username.

T1036.001
Invalid Code Signature

APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.”

T1053.005
Scheduled Task

APT37 has created scheduled tasks to run malicious scripts on a compromised host.

T1055
Process Injection

APT37 injects its malware variant, ROKRAT, into the cmd.exe process.

T1057
Process Discovery

APT37's Freenki malware lists running processes using the Microsoft Windows API.

T1059
Command and Scripting Interpreter

APT37 has used Ruby scripts to execute payloads.

T1059.003
Windows Command Shell

APT37 has used the command-line interface.

T1059.005
Visual Basic

APT37 executes shellcode and a VBA script to decode Base64 strings.

T1059.006
Python

APT37 has used Python scripts to execute payloads.

T1071.001
Web Protocols

APT37 uses HTTPS to conceal C2 communications.

T1082
System Information Discovery

APT37 collects the computer name, the BIOS model, and execution path.

T1102.002
Bidirectional Communication

APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.

View all 29 procedure examples

Software13

Campaigns0

None recorded.

References3

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.
  2. Securelist ScarCruft Jun 2016 Open source
    Raiu, C., and Ivanov, A. (2016, June 17). Operation Daybreak. Retrieved February 15, 2018.
  3. Talos Group123 Open source
    Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.