Scarcruft

2016-06-17 • KasperskyOperation Daybreak

ScarCruft is a codename introduced by Kaspersky for an APT group first identified through Operation Daybreak, a March 2016 spear-phishing campaign that used a previously unknown Adobe Flash Player exploit to compromise more than two dozen high-profile victims in Russia, Nepal, South Korea, China, India, Kuwait, and Romania; the group was also linked to an earlier campaign, Operation Erebus, which used watering-hole attacks with a separate Flash exploit. Kaspersky assessed ScarCruft's tradecraft and tooling as professional and well above average for a group that had, at the time, managed to remain largely undetected. In subsequent Kaspersky reporting, ScarCruft, also referred to elsewhere as APT37 or Temp.Reaper, continued targeting North Korean defectors, journalists covering North Korea, and government organizations tied to the Korean Peninsula. One investigation found the group had compromised a victim's social media and email accounts to approach and spear-phish the victim's associates, deploying PowerShell, Windows, and Android malware that shared a common command-and-control scheme, with related activity traced back to at least mid-2020.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster