Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT37

🇰🇵APT37

🇰🇵 APT37 is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 120 MITRE ATT&CK techniques, with 5 threat-intel articles citing them. Active in our corpus from 2026-05-05 to 2026-05-28.

crit 5
View full actor card → All threat actors MITRE ATT&CK group spec (G0067) ↗
26Use cases
5Articles
120Techniques
13IOCs

Known aliases

APT37ScarCruftReaperInkySquidRicochet ChollimaGroup123TEMP.Reaper

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1020 · Automated ExfiltrationT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1027.003 · SteganographyT1027.009 · Embedded PayloadsT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.001 · Invalid Code SignatureT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1060 · T1060T1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.004 · DNST1074.001 · Local Data StagingT1074.002 · Remote Data StagingT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1090 · ProxyT1090.001 · Internal ProxyT1090.002 · External ProxyT1090.003 · Multi-hop ProxyT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1123 · Audio CaptureT1125 · Video CaptureT1132.001 · Standard EncodingT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.011 · Rundll32T1219 · Remote Access ToolsT1406 · T1406T1407 · T1407T1420 · T1420T1422 · T1422T1426 · T1426T1429 · T1429T1430 · T1430T1437.001 · T1437.001T1474.003 · T1474.003T1480.001 · Environmental KeyingT1481.002 · T1481.002T1486 · Data Encrypted for ImpactT1497 · Virtualization/Sandbox EvasionT1513 · T1513T1529 · System Shutdown/RebootT1532 · T1532T1533 · T1533T1541 · T1541T1546.016 · Installer PackagesT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1550.001 · Application Access TokenT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1560 · Archive Collected DataT1561.002 · Disk Structure WipeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1583 · Acquire InfrastructureT1583.001 · DomainsT1583.003 · Virtual Private ServerT1583.004 · ServerT1584.004 · ServerT1584.006 · Web ServicesT1585.003 · Cloud AccountsT1587.001 · MalwareT1588.002 · ToolT1588.006 · VulnerabilitiesT1595.002 · Vulnerability ScanningT1595.003 · Wordlist ScanningT1608 · Stage CapabilitiesT1608.001 · Upload MalwareT1608.002 · Upload ToolT1636.002 · T1636.002T1636.003 · T1636.003T1636.004 · T1636.004T1643 · T1643T1646 · T1646

Detection use cases (26)

APT37 (ScarCruft) HWP/LNK spearphish → mshta/PowerShell loader chain for RokRat AI · profile SΣDD APT37 RokRat/Chinotto cloud-storage C2 to pCloud/Yandex/Dropbox from non-browser host AI · profile SDD Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency Bespoke axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Trusted vendor binary / installer launching unusual children Internal EchoCreep Discord API beacon from non-browser process (Webworm 2025) Bespoke GraphWorm OneDrive /createUploadSession C2 from non-Office process Bespoke AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match

Threat-intel articles (5)

Tracked indicators

Domains (8)

book-happy.needbinding.i github.com/anjsdgasdf/Wo nama-belakang.nebao.icu nebao.icu needbinding.icu sqgame.com.cn sqgame.net xiazai.sqgame.com.cn

IP addresses (5)

104.243.23.43 108.61.200.151 144.168.60.233 45.77.13.67 64.176.85.158

CVEs (3)

CVE-2017-7692 CVE-2023-38831 CVE-2024-42009