Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT37

🇰🇵APT37

🇰🇵 APT37 is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 128 MITRE ATT&CK techniques, with 6 threat-intel articles citing them. Active in our corpus from 2025-10-23 to 2026-05-28.

crit 6
View full actor card → All threat actors MITRE ATT&CK group spec (G0067) ↗
26Use cases
6Articles
128Techniques
41IOCs

Known aliases

APT37ScarCruftReaperInkySquidRicochet ChollimaGroup123TEMP.Reaper

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1020 · Automated ExfiltrationT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1027.003 · SteganographyT1027.007 · Dynamic API ResolutionT1027.009 · Embedded PayloadsT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.001 · Invalid Code SignatureT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1060 · T1060T1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.004 · DNST1074.001 · Local Data StagingT1074.002 · Remote Data StagingT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1090 · ProxyT1090.001 · Internal ProxyT1090.002 · External ProxyT1090.003 · Multi-hop ProxyT1102 · Web ServiceT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1123 · Audio CaptureT1125 · Video CaptureT1129 · Shared ModulesT1132.001 · Standard EncodingT1134.002 · Create Process with TokenT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.011 · Rundll32T1219 · Remote Access ToolsT1406 · T1406T1407 · T1407T1420 · T1420T1422 · T1422T1426 · T1426T1429 · T1429T1430 · T1430T1437.001 · T1437.001T1474.003 · T1474.003T1480.001 · Environmental KeyingT1481.002 · T1481.002T1486 · Data Encrypted for ImpactT1497 · Virtualization/Sandbox EvasionT1513 · T1513T1529 · System Shutdown/RebootT1532 · T1532T1533 · T1533T1541 · T1541T1546.016 · Installer PackagesT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1550.001 · Application Access TokenT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1560 · Archive Collected DataT1561.002 · Disk Structure WipeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.001 · Symmetric CryptographyT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1583 · Acquire InfrastructureT1583.001 · DomainsT1583.003 · Virtual Private ServerT1583.004 · ServerT1584.004 · ServerT1584.006 · Web ServicesT1585.003 · Cloud AccountsT1587.001 · MalwareT1588.002 · ToolT1588.006 · VulnerabilitiesT1595.002 · Vulnerability ScanningT1595.003 · Wordlist ScanningT1608 · Stage CapabilitiesT1608.001 · Upload MalwareT1608.002 · Upload ToolT1620 · Reflective Code LoadingT1636.002 · T1636.002T1636.003 · T1636.003T1636.004 · T1636.004T1643 · T1643T1646 · T1646

Detection use cases (26)

APT37 (ScarCruft) ROKRAT cloud C2 — non-browser process talking to pCloud/Yandex/Dropbox/Box APIs AI · profile SΣDD APT37 Hancom HWP/HOffice spawning script interpreters — ScarCruft Korean-lure spearphishing chain AI · profile SΣDD Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency Bespoke axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Trusted vendor binary / installer launching unusual children Internal EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules MITRE match

Threat-intel articles (6)

Tracked indicators

Domains (22)

anvil.org.ph bandarpowder.com book-happy.needbinding.i coralsunmarine.com ecudecode.mx galaterrace.com github.com/anjsdgasdf/Wo kazitradebd.com mediostresbarbas.com.ar mnmathleague.org nama-belakang.nebao.icu nebao.icu needbinding.icu oldlinewoodwork.com partnerls.pl pierregems.com scgestor.com.br spaincaramoon.com sqgame.com.cn sqgame.net trainingpharmacist.co.uk xiazai.sqgame.com.cn

IP addresses (19)

104.21.80.1 104.243.23.43 104.247.162.67 108.181.92.71 108.61.200.151 144.168.60.233 152.42.239.211 172.67.193.139 185.148.129.24 193.39.187.165 23.111.133.162 45.148.29.122 45.77.13.67 64.176.85.158 66.29.144.75 70.32.24.131 75.102.23.3 77.55.252.111 95.217.119.214

CVEs (3)

CVE-2017-7692 CVE-2023-38831 CVE-2024-42009