🇰🇵APT37
🇰🇵 APT37 is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 120 MITRE ATT&CK techniques, with 5 threat-intel articles citing them. Active in our corpus from 2026-05-05 to 2026-05-28.
crit 5
26Use cases
5Articles
120Techniques
13IOCs
Known aliases
APT37ScarCruftReaperInkySquidRicochet ChollimaGroup123TEMP.Reaper
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1020 · Automated ExfiltrationT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1027.003 · SteganographyT1027.009 · Embedded PayloadsT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.001 · Invalid Code SignatureT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1060 · T1060T1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.004 · DNST1074.001 · Local Data StagingT1074.002 · Remote Data StagingT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1090 · ProxyT1090.001 · Internal ProxyT1090.002 · External ProxyT1090.003 · Multi-hop ProxyT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1123 · Audio CaptureT1125 · Video CaptureT1132.001 · Standard EncodingT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.011 · Rundll32T1219 · Remote Access ToolsT1406 · T1406T1407 · T1407T1420 · T1420T1422 · T1422T1426 · T1426T1429 · T1429T1430 · T1430T1437.001 · T1437.001T1474.003 · T1474.003T1480.001 · Environmental KeyingT1481.002 · T1481.002T1486 · Data Encrypted for ImpactT1497 · Virtualization/Sandbox EvasionT1513 · T1513T1529 · System Shutdown/RebootT1532 · T1532T1533 · T1533T1541 · T1541T1546.016 · Installer PackagesT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1550.001 · Application Access TokenT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1560 · Archive Collected DataT1561.002 · Disk Structure WipeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1583 · Acquire InfrastructureT1583.001 · DomainsT1583.003 · Virtual Private ServerT1583.004 · ServerT1584.004 · ServerT1584.006 · Web ServicesT1585.003 · Cloud AccountsT1587.001 · MalwareT1588.002 · ToolT1588.006 · VulnerabilitiesT1595.002 · Vulnerability ScanningT1595.003 · Wordlist ScanningT1608 · Stage CapabilitiesT1608.001 · Upload MalwareT1608.002 · Upload ToolT1636.002 · T1636.002T1636.003 · T1636.003T1636.004 · T1636.004T1643 · T1643T1646 · T1646
Detection use cases (26)
APT37 (ScarCruft) HWP/LNK spearphish → mshta/PowerShell loader chain for RokRat APT37 RokRat/Chinotto cloud-storage C2 to pCloud/Yandex/Dropbox from non-browser host Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Trusted vendor binary / installer launching unusual children EchoCreep Discord API beacon from non-browser process (Webworm 2025) GraphWorm OneDrive /createUploadSession C2 from non-Office process AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public EgressThreat-intel articles (5)
crit ESET APT Activity Report Q4 2025–Q1 2026 · 2026-05-28
crit Webworm: New burrowing techniques · 2026-05-20
Tracked indicators
Domains (8)
book-happy.needbinding.i github.com/anjsdgasdf/Wo nama-belakang.nebao.icu nebao.icu needbinding.icu sqgame.com.cn sqgame.net xiazai.sqgame.com.cnIP addresses (5)
104.243.23.43 108.61.200.151 144.168.60.233 45.77.13.67 64.176.85.158CVEs (3)
CVE-2017-7692 CVE-2023-38831 CVE-2024-42009