🇰🇵APT37
🇰🇵 APT37 is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 128 MITRE ATT&CK techniques, with 6 threat-intel articles citing them. Active in our corpus from 2025-10-23 to 2026-05-28.
crit 6
26Use cases
6Articles
128Techniques
41IOCs
Known aliases
APT37ScarCruftReaperInkySquidRicochet ChollimaGroup123TEMP.Reaper
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1020 · Automated ExfiltrationT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.007 · Cloud ServicesT1027 · Obfuscated Files or InformationT1027.003 · SteganographyT1027.007 · Dynamic API ResolutionT1027.009 · Embedded PayloadsT1027.013 · Encrypted/Encoded FileT1033 · System Owner/User DiscoveryT1036.001 · Invalid Code SignatureT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1060 · T1060T1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.004 · DNST1074.001 · Local Data StagingT1074.002 · Remote Data StagingT1078.004 · Cloud AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1090 · ProxyT1090.001 · Internal ProxyT1090.002 · External ProxyT1090.003 · Multi-hop ProxyT1102 · Web ServiceT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1113 · Screen CaptureT1115 · Clipboard DataT1119 · Automated CollectionT1120 · Peripheral Device DiscoveryT1123 · Audio CaptureT1125 · Video CaptureT1129 · Shared ModulesT1132.001 · Standard EncodingT1134.002 · Create Process with TokenT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1218.011 · Rundll32T1219 · Remote Access ToolsT1406 · T1406T1407 · T1407T1420 · T1420T1422 · T1422T1426 · T1426T1429 · T1429T1430 · T1430T1437.001 · T1437.001T1474.003 · T1474.003T1480.001 · Environmental KeyingT1481.002 · T1481.002T1486 · Data Encrypted for ImpactT1497 · Virtualization/Sandbox EvasionT1513 · T1513T1529 · System Shutdown/RebootT1532 · T1532T1533 · T1533T1541 · T1541T1546.016 · Installer PackagesT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1550.001 · Application Access TokenT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1559.002 · Dynamic Data ExchangeT1560 · Archive Collected DataT1561.002 · Disk Structure WipeT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.001 · Symmetric CryptographyT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1583 · Acquire InfrastructureT1583.001 · DomainsT1583.003 · Virtual Private ServerT1583.004 · ServerT1584.004 · ServerT1584.006 · Web ServicesT1585.003 · Cloud AccountsT1587.001 · MalwareT1588.002 · ToolT1588.006 · VulnerabilitiesT1595.002 · Vulnerability ScanningT1595.003 · Wordlist ScanningT1608 · Stage CapabilitiesT1608.001 · Upload MalwareT1608.002 · Upload ToolT1620 · Reflective Code LoadingT1636.002 · T1636.002T1636.003 · T1636.003T1636.004 · T1636.004T1643 · T1643T1646 · T1646
Detection use cases (26)
APT37 (ScarCruft) ROKRAT cloud C2 — non-browser process talking to pCloud/Yandex/Dropbox/Box APIs APT37 Hancom HWP/HOffice spawning script interpreters — ScarCruft Korean-lure spearphishing chain Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Trusted vendor binary / installer launching unusual children EchoCreep Discord API beacon from non-browser process (Webworm 2025) GraphWorm OneDrive /createUploadSession C2 from non-Office process Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modulesThreat-intel articles (6)
crit ESET APT Activity Report Q4 2025–Q1 2026 · 2026-05-28
crit Webworm: New burrowing techniques · 2026-05-20
crit Gotta fly: Lazarus targets the UAV sector · 2025-10-23
Tracked indicators
Domains (22)
anvil.org.ph bandarpowder.com book-happy.needbinding.i coralsunmarine.com ecudecode.mx galaterrace.com github.com/anjsdgasdf/Wo kazitradebd.com mediostresbarbas.com.ar mnmathleague.org nama-belakang.nebao.icu nebao.icu needbinding.icu oldlinewoodwork.com partnerls.pl pierregems.com scgestor.com.br spaincaramoon.com sqgame.com.cn sqgame.net trainingpharmacist.co.uk xiazai.sqgame.com.cnIP addresses (19)
104.21.80.1 104.243.23.43 104.247.162.67 108.181.92.71 108.61.200.151 144.168.60.233 152.42.239.211 172.67.193.139 185.148.129.24 193.39.187.165 23.111.133.162 45.148.29.122 45.77.13.67 64.176.85.158 66.29.144.75 70.32.24.131 75.102.23.3 77.55.252.111 95.217.119.214CVEs (3)
CVE-2017-7692 CVE-2023-38831 CVE-2024-42009