Initial Access
2 techniques·derived
HWP Korean word-processor documents, near-universal in South Korean government use. Watering holes on defector-support and news sites.
Prolific browser zero-day developer, focused on South Korean targets and North Korean defectors.
APT37, commonly reported as ScarCruft, is the most capable exploit developer in the DPRK's cyber apparatus. Where Kimsuky relies on social engineering and Lazarus on volume, APT37 repeatedly finds and weaponises browser and document zero-days.
It has burned Flash zero-days, Internet Explorer zero-days, and Windows kernel escalations — a research capability that is expensive to build and maintain, and which the group has consistently directed at a narrow target set rather than spending broadly.
That target set is politically sensitive: North Korean defectors and the organisations that resettle and support them, South Korean journalists covering DPRK affairs, human rights groups documenting conditions inside the country, and government and academic institutions working Korea policy. Reporting has also documented targeting of individuals connected to defector networks in Japan, Vietnam, and the Middle East.
The group's flagship implant, ROKRAT, is notable for using legitimate cloud services — Dropbox, Yandex Disk, pCloud, Google Drive — for both command and control and exfiltration. Traffic to these services is ordinary in most enterprises and encrypted by default, so the implant's network activity is close to indistinguishable from an employee syncing files.
Unusually for a DPRK group, APT37 is assessed as reporting to the Ministry of State Security rather than the Reconnaissance General Bureau.
Down to the named unit where public evidence supports it.
Assessed as North Korean state-sponsored with high confidence by Mandiant/FireEye, based on malware development artifacts including North Korean IP addresses in build environments, Korean-language resources, and targeting exclusively aligned with DPRK interests. The specific attribution to the Ministry of State Security rather than the Reconnaissance General Bureau is an industry assessment rather than a government finding, and is held with lower confidence than the state-level attribution.
Attributing sources
10 designators across 9 organisations.
2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
TA### ('Threat Actor'), numbered sequentially in order of first tracking.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Flagship implant using Dropbox, Yandex Disk, pCloud, and Google Drive for C2 and exfiltration — network traffic indistinguishable from ordinary file sync.
Malpedia ↗Successor implant delivered via a multi-stage chain, used against journalists and defector organisations.
PowerShell and Windows backdoor with an Android counterpart, used for surveillance of individuals.
Earlier implant families with cloud-service C2, supporting screenshots and audio capture.
Module enumerating nearby Bluetooth devices — an unusual capability suggesting interest in physical proximity mapping.
Mobile implants targeting individuals' phones alongside desktop compromise.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT37 | ||
|---|---|---|---|---|
| CVE-2024-381780-day | — | — | 1 May 2024 | Windows Scripting Engine memory corruption exploited as a zero-day via a compromised advertising server ('Code-on-Toast' campaign).SRCAhnLab / ROK NCSC ↗ |
| CVE-2022-411280-day | — | — | 31 Oct 2022 | Internet Explorer JScript engine zero-day delivered inside a Word document referencing the Itaewon crowd-crush disaster — exploiting a national tragedy for lure credibility days after it occurred.SRCGoogle Threat Analysis Group ↗ |
| CVE-2018-48780-dayKEVransomware | 9.8 | Adobe Flash PlayerAdobe | 31 Jan 2018 | Adobe Flash use-after-free exploited as a zero-day against South Korean targets, including individuals researching North Korea, prior to Adobe's patch.SRCCisco Talos ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 May 2017 | OLE2link RTF exploit used to deliver ROKRAT in campaigns against South Korean targets.SRCCisco Talos ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
HWP Korean word-processor documents, near-universal in South Korean government use. Watering holes on defector-support and news sites.
1 technique·derived
Repeated use of browser and document zero-days.
1 technique·derived
Registry Run Keys.
1 technique·derived
Payloads concealed within image files.
1 technique·derived
Bluetooth device enumeration.
2 techniques·derived
Screen Capture, Audio Capture.
1 technique·derived
Cloud storage services as C2 — the group's signature.
1 technique·derived
Exfiltration to Cloud Storage.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
HWP Korean word-processor documents, near-universal in South Korean government use
Watering holes on defector-support and news sites
Repeated use of browser and document zero-days
Payloads concealed within image files
Bluetooth device enumeration
Cloud storage services as C2 — the group's signature
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Overlapping target sets across South Korean policy and defector communities; distinct toolsets and, per assessment, different services.
Both DPRK state actors; APT37 assessed as MSS rather than RGB.
Curated links to the reports that established what is known about this group.