Threat group.View on attack.mitre.org
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
APT37 has collected data from victims' local systems. |
| T1027 Obfuscated Files or Information |
APT37 obfuscates strings and payloads. |
| T1027.003 Steganography |
APT37 uses steganography to send images to users that are embedded with shellcode. |
| T1033 System Owner/User Discovery |
APT37 identifies the victim username. |
| T1036.001 Invalid Code Signature |
APT37 has signed its malware with an invalid digital certificates listed as “Tencent Technology (Shenzhen) Company Limited.” |
| T1053.005 Scheduled Task |
APT37 has created scheduled tasks to run malicious scripts on a compromised host. |
| T1055 Process Injection |
APT37 injects its malware variant, ROKRAT, into the cmd.exe process. |
| T1057 Process Discovery |
APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| T1059 Command and Scripting Interpreter |
APT37 has used Ruby scripts to execute payloads. |
| T1059.003 Windows Command Shell |
APT37 has used the command-line interface. |
| T1059.005 Visual Basic |
APT37 executes shellcode and a VBA script to decode Base64 strings. |
| T1059.006 Python |
APT37 has used Python scripts to execute payloads. |
| T1071.001 Web Protocols |
APT37 uses HTTPS to conceal C2 communications. |
| T1082 System Information Discovery |
APT37 collects the computer name, the BIOS model, and execution path. |
| T1102.002 Bidirectional Communication |
APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.