Ricochet Chollima

2019-02-19 • Crowd Strikehttps://adversary.crowdstrike.com/en-US/adversary/ricochet-chollima/

Ricochet Chollima, also known in industry reporting as APT37, Inky Squid, RedEyes, ScarCruft, and Reaper, is a North Korea-nexus threat actor group active since at least 2012 that has primarily targeted entities in South Korea while also striking organizations in Japan, Vietnam, the Middle East, and elsewhere, with a focus on chemical, electronics, manufacturing, aerospace, automotive, and healthcare verticals. Its toolset includes Windows UAC bypass techniques, HTTPS-based command and control, an MBR wiper, Flash exploits, steganography, and malware families such as RokRAT, Bluelight, and NavRAT. In 2024 the group used LNK files to distribute RokRAT and targeted Southeast Asian entities with VeilShell RAT as part of a campaign tracked as Shrouded Sleep, while also leveraging a Microsoft browser zero-day vulnerability. The group has also expanded into mobile espionage, distributing KoSpy, an Android spyware family that masquerades as utility applications, retrieves configuration data from cloud infrastructure to dynamically enable or disable itself, and collects SMS messages, call logs, location, files, and audio from Korean and English-speaking targets via Google Play and third-party app stores.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster