APT37

2018-02-20 • MandiantAPT37 (Reaper): The Overlooked North Korean Actor

FireEye (later Mandiant) introduced the name APT37 (Reaper) in a 2018 special report examining a suspected North Korean cyber-espionage group first observed via a February 2018 Adobe Flash zero-day blog post, assessing that APT37 aligns with activity separately reported as Scarcruft and Group123. FireEye assessed with high confidence that APT37 operates on behalf of the North Korean government, active since at least 2012 and focused primarily on covert intelligence gathering supporting North Korea's military, political, and economic interests. From 2014 to 2017 the group concentrated on South Korean government, military, defense-industrial, and media targets before expanding in 2017 to Japan, Vietnam, the Middle East, and additional sectors including chemicals, electronics, manufacturing, aerospace, automotive, and healthcare, alongside continued targeting of North Korean defectors and human-rights organizations. APT37 relies on spear phishing with Hangul Word Processor exploits and strategic web compromises, rapid adoption of zero-day vulnerabilities, cloud-hosted and compromised-site command and control, and a malware suite including the DOGCALL backdoor and the RUHAPPY wiper capable of overwriting a system's master boot record.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster