Skip to content
North KoreaState-SponsoredActiveMITRE G0067Malpedia ↗

APT37

Prolific browser zero-day developer, focused on South Korean targets and North Korean defectors.

Open MITRE Navigator layer ↗Download profile JSON
Active
2012–present
Motivation
Espionage
Aliases
10
Exploited CVEs
4
ATT&CK techniques
10
Cited sources
9

Overview

APT37, commonly reported as ScarCruft, is the most capable exploit developer in the DPRK's cyber apparatus. Where Kimsuky relies on social engineering and Lazarus on volume, APT37 repeatedly finds and weaponises browser and document zero-days.

It has burned Flash zero-days, Internet Explorer zero-days, and Windows kernel escalations — a research capability that is expensive to build and maintain, and which the group has consistently directed at a narrow target set rather than spending broadly.

That target set is politically sensitive: North Korean defectors and the organisations that resettle and support them, South Korean journalists covering DPRK affairs, human rights groups documenting conditions inside the country, and government and academic institutions working Korea policy. Reporting has also documented targeting of individuals connected to defector networks in Japan, Vietnam, and the Middle East.

The group's flagship implant, ROKRAT, is notable for using legitimate cloud services — Dropbox, Yandex Disk, pCloud, Google Drive — for both command and control and exfiltration. Traffic to these services is ordinary in most enterprises and encrypted by default, so the implant's network activity is close to indistinguishable from an employee syncing files.

Unusually for a DPRK group, APT37 is assessed as reporting to the Ministry of State Security rather than the Reconnaissance General Bureau.

Attribution

Down to the named unit where public evidence supports it.

North KoreaMSS — Ministry of State Security (assessed)Moderate confidence

Assessed as North Korean state-sponsored with high confidence by Mandiant/FireEye, based on malware development artifacts including North Korean IP addresses in build environments, Korean-language resources, and targeting exclusively aligned with DPRK interests. The specific attribution to the Ministry of State Security rather than the Reconnaissance General Bureau is an industry assessment rather than a government finding, and is held with lower confidence than the state-level attribution.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 9 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • APT37

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Ruby SleetFormerly CERIUM

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Ricochet Chollima

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT37
  • Reaper

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • NICKEL FOXCROFT

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Velvet ChollimapartialBoundary between APT37 and Kimsuky clusters varies by vendor

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Kaspersky GReAT

index ↗
  • ScarCruft

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Proofpoint

index ↗
  • TA-RedAntpartialAhnLab designator for an overlapping cluster

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • Group123Cisco Talos designator adopted in U.S. reporting

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

ROKRATbackdoor

Flagship implant using Dropbox, Yandex Disk, pCloud, and Google Drive for C2 and exfiltration — network traffic indistinguishable from ordinary file sync.

Malpedia ↗
GOLDBACKDOORbackdoor

Successor implant delivered via a multi-stage chain, used against journalists and defector organisations.

Chinottobackdoor

PowerShell and Windows backdoor with an Android counterpart, used for surveillance of individuals.

DOGCALL / KARAEbackdoor

Earlier implant families with cloud-service C2, supporting screenshots and audio capture.

Bluetooth harvesterutility

Module enumerating nearby Bluetooth devices — an unusual capability suggesting interest in physical proximity mapping.

RokRAT Android variantsmalware

Mobile implants targeting individuals' phones alongside desktop compromise.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT37
CVE-2024-381780-day1 May 2024Windows Scripting Engine memory corruption exploited as a zero-day via a compromised advertising server ('Code-on-Toast' campaign).SRCAhnLab / ROK NCSC
CVE-2022-411280-day31 Oct 2022Internet Explorer JScript engine zero-day delivered inside a Word document referencing the Itaewon crowd-crush disaster — exploiting a national tragedy for lure credibility days after it occurred.SRCGoogle Threat Analysis Group
CVE-2018-48780-dayKEVransomware9.831 Jan 2018Adobe Flash use-after-free exploited as a zero-day against South Korean targets, including individuals researching North Korea, prior to Adobe's patch.SRCCisco Talos
CVE-2017-0199KEVransomware7.81 May 2017OLE2link RTF exploit used to deliver ROKRAT in campaigns against South Korean targets.SRCCisco Talos

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

8 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 8 tactics · 6 with actor-specific notes

Initial Access

2

Execution

1

Defense Evasion

1

Discovery

1

Command and Control

1

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.