SYMBOLCOMMON_NAMEaka. SYNONYMS

APT37  (Back to overview)

aka: APT 37, APT-C-28, ATK4, G0067, Group 123, Group123, InkySquid, Moldy Pisces, Operation Daybreak, Operation Erebus, PLAIN NEPTUNE, Reaper, Reaper Group, Red Eyes, Ricochet Chollima, ScarCruft, Venus 121

APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its targeting beyond the Korean peninsula to include Japan, Vietnam and the Middle East, and to a wider range of industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive and healthcare entities


Associated Families
apk.chinotto apk.kevdroid win.poorweb win.unidentified_067 apk.kospy win.bluelight win.chinotto win.final1stspy win.freenki win.goldbackdoor win.konni win.nokki win.open_carrot win.poohmilk win.rustonotto win.starcruft win.birdcall win.rokrat

References
2026-07-24 ⋅ Google ⋅ Google Threat Intelligence Group
Updated Cyber Threat Actor Naming System
APT15 APT20 APT27 APT28 APT29 APT30 APT31 APT33 APT35 APT37 APT39 APT40 APT41 APT42 APT45 APT5 BlackTech Callisto Conference Crew FIN11 FIN6 FIN7 FIN8 MuddyWater MUSTANG PANDA Naikon OilRig Sandworm TEMP.Hermit Tick Tonto Team Turla UAC-0020 UNC1069 UNC1088 UNC2814
2026-05-28 ⋅ ESET Research ⋅ ESET Research
ESET APT Activity Report Q4 2025–Q1 2026
WAVESHAPER BirdCall BLINDINGCAN RokRAT Rook Tiger RAT
2026-05-05 ⋅ ESET Research ⋅ Filip Jurčacko
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
BirdCall
2025-12-21 ⋅ Genians ⋅ Genians
Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks
RokRAT
2025-11-05 ⋅ ESET Research ⋅ ESET Research
ESET APT Activity Report (April 2025 – September 2025): Russia-Aligned APTs Ramp Up Attacks Against Ukraine and Its Strategic Partners
BACKORDER BloodAlchemy ImprudentCook RokRAT ScoringMathTea
2025-09-08 ⋅ Zscaler ⋅ Seongsu Park
APT37 Targets Windows with Rust Backdoor and Python Loader
Rustonotto
2025-07-21 ⋅ AhnLab ⋅ ASEC
RokRAT Malware Using Malicious Hangul (.HWP) Documents
RokRAT
2025-05-12 ⋅ Genians ⋅ Genians
Analysis of APT37 Attack Case Disguised as a Think Tank for National Security Strategy in South Korea (Operation. ToyBox Story)
RokRAT
2025-05-10 ⋅ cocomelonc ⋅ cocomelonc
Malware development trick 47: simple Windows clipboard hijacking. Simple C example.
CosmicDuke RokRAT
2025-05-01 ⋅ cocomelonc ⋅ cocomelonc
Malware development trick 46: simple Windows keylogger. Simple C example.
MyDoom Nokki RokRAT
2025-03-12 ⋅ Lookout ⋅ Lookout
Lookout Discovers New Spyware by North Korean APT37
KoSpy
2025-03-01 ⋅ ZW01f ⋅ Mohamed Ezat
An in-depth analysis of APT37’s latest campaign
RokRAT
2025-02-20 ⋅ Cyber Security News ⋅ Balaji N
APT-C-28 Group Launched New Cyber Attack With Fileless RokRat Malware
RokRAT
2024-10-16 ⋅ AhnLab ⋅ ASEC
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178)
APT37
2024-05-07 ⋅ AhnLab ⋅ ASEC
LNK File Disguised as Certificate Distributing RokRAT Malware
RokRAT
2024-03-04 ⋅ ⋅ Weixin ⋅ Hunting Shadow Lab
Shadow Hunting: Analysis of APT37’s attack activities against South Korea using North Korean political topics
RokRAT
2024-03-01 ⋅ 0x0v1 ⋅ Ovi
APT37's ROKRAT HWP Object Linking and Embedding
RokRAT
2024-02-21 ⋅ DCSO ⋅ Jiro Minier, Johann Aydinbas, Kritika Roy, Olivia Hayward
To Russia With Love: Assessing a KONNI-Backdoored Suspected Russian Consular Software Installer
Konni
2023-12-27 ⋅ ⋅ Wezard4u ⋅ Sakai
Malicious code impersonating the National Tax Service created by Konni
Konni
2023-11-10 ⋅ NSFOCUS ⋅ NSFOCUS
The New APT Group DarkCasino and the Global Surge in WinRAR 0-Day Exploits
Cobalt Strike Konni DarkCasino Opal Sleet
2023-09-25 ⋅ 0x0v1 ⋅ Ovi
REArchive: Reverse engineering APT37’s GOLDBACKDOOR dropper
GOLDBACKDOOR
2023-08-07 ⋅ SentinelOne ⋅ Aleksandar Milenkoski, Tom Hegel
Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company
OpenCarrot
2023-06-06 ⋅ Security Intelligence ⋅ Agnes Ramos-Beauchamp, Claire Zaboeva, Joshua Chung, Melissa Frydrych
ITG10 Likely Targeting South Korean Entities of Interest to the Democratic People’s Republic of Korea (DPRK)
RokRAT
2023-05-01 ⋅ Check Point Research ⋅ Check Point Research
Chain Reaction: RokRAT's Missing Link
Amadey RokRAT
2023-04-26 ⋅ AhnLab ⋅ bghjmun
RokRAT Malware Distributed Through LNK Files (*.lnk): RedEyes (ScarCruft)
RokRAT
2023-03-28 ⋅ ThreatMon ⋅ Seyit Sigirci (@h3xecute), ThreatMon Malware Research Team
Chinotto Backdoor Technical Analysis of the APT Reaper’s Powerful Weapon
Chinotto
2023-03-23 ⋅ Medium s2wlab ⋅ BLKSMTH, S2W TALON
Scarcruft Bolsters Arsenal for targeting individual Android devices
RambleOn RokRAT
2023-03-21 ⋅ Zscaler ⋅ Naveen Selvan, Sudeep Singh
The Unintentional Leak: A glimpse into the attack vectors of APT37
Chinotto
2023-03-16 ⋅ Sekoia ⋅ Threat & Detection Research Team
Peeking at Reaper’s surveillance operations
Chinotto
2023-01-27 ⋅ ⋅ ThorCERT ⋅ Dongwook Kim, Seulgi Lee, Taewoo Lee
TTPs #9: Analyzing Attack Strategies to Monitor Individuals' Daily Lives
Chinotto
2023-01-01 ⋅ ThreatMon ⋅ Seyit Sigirci (@h3xecute), ThreatMon Malware Research Team
The Konni APT Chronicle: Tracing Their Intelligence-Driven Attack Chain
Konni
2023-01-01 ⋅ ThreatMon ⋅ Seyit Sigirci (@h3xecute), ThreatMon Malware Research Team
Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector
RokRAT
2022-12-05 ⋅ ⋅ KISA ⋅ KrCERT
TTPs#9: Analyzing the attack strategy monitoring the daily life of individuals
Chinotto
2022-09-28 ⋅ Twitter (@ESETresearch) ⋅ ESET Research
Twitter Thread linking CloudMensis to RokRAT / ScarCruft
CloudMensis RokRAT
2022-09-06 ⋅ cocomelonc ⋅ cocomelonc
Malware development tricks: parent PID spoofing. Simple C++ example.
Cobalt Strike Konni
2022-07-23 ⋅ BleepingComputer ⋅ Bill Toulas
North Korean hackers attack EU targets with Konni RAT malware
Konni
2022-07-20 ⋅ Securonix Threat Labs ⋅ Den Iyzvyk, Oleg Kolesnikov, Tim Peck
STIFF#BIZON Detection Using Securonix – New Attack Campaign Observed Possibly Linked to Konni/APT37 (North Korea) - Securonix
Konni Opal Sleet
2022-07-18 ⋅ Palo Alto Networks Unit 42 ⋅ Unit 42
Moldy Pisces
RokRAT APT37
2022-05-02 ⋅ cocomelonc ⋅ cocomelonc
Malware development: persistence - part 3. COM DLL hijack. Simple C++ example
Agent.BTZ Ave Maria Konni Mosquito TurlaRPC
2022-04-28 ⋅ PWC ⋅ PWC UK
Cyber Threats 2021: A Year in Retrospect (Annex)
Cobalt Strike Conti PlugX RokRAT Inception Framework Red Menshen
2022-04-21 ⋅ Stairwell ⋅ Silas Cutler
The ink-stained trail of GOLDBACKDOOR
GOLDBACKDOOR
2022-01-26 ⋅ Malwarebytes ⋅ Roberto Santos
KONNI evolves into stealthier RAT
Konni
2022-01-12 ⋅ BleepingComputer ⋅ Ionut Ilascu
Hackers take over diplomat's email, target Russian deputy minister
Konni
2022-01-05 ⋅ Lumen ⋅ Danny Adamitis, Steve Rudd
New Konni Campaign Kicks Off the New Year by Targeting Russian Ministry of Foreign Affairs
Konni
2022-01-03 ⋅ Cluster25 ⋅ Cluster25
North Korean Group “KONNI” Targets The Russian Diplomatic Sector With New Versions Of Malware Implants
Konni
2021-12-06 ⋅ cyble ⋅ Cyble
APT37 Using a New Android Spyware, Chinotto
Chinotto
2021-11-29 ⋅ Kaspersky ⋅ GReAT
ScarCruft surveilling North Korean defectors and human rights activists
Chinotto Chinotto PoorWeb
2021-08-24 ⋅ Volexity ⋅ Damien Cash, Josh Grunzweig, Steven Adair, Thomas Lancaster
North Korean BLUELIGHT Special: InkySquid Deploys RokRAT
RokRAT
2021-08-20 ⋅ Malwarebytes ⋅ Hossein Jazi
New variant of Konni malware used in campaign targetting Russia
Konni
2021-08-17 ⋅ Volatility Labs ⋅ Damien Cash, Josh Grunzweig, Matthew Meltzer, Steven Adair, Thomas Lancaster
North Korean APT37 / InkySquid Infects Victims Using Browser Exploits
BLUELIGHT APT37
2021-07-14 ⋅ Medium s2wlab ⋅ Jaeki Kim
Matryoshka : Variant of ROKRAT, APT37 (Scarcruft)
RokRAT
2021-02-18 ⋅ PTSecurity ⋅ PTSecurity
https://www.ptsecurity.com/ww-en/analytics/antisandbox-techniques/
Poet RAT Gravity RAT Ketrican Okrum OopsIE Remcos RogueRobinNET RokRAT SmokeLoader
2021-01-06 ⋅ Malwarebytes ⋅ Hossein Jazi
Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat
RokRAT
2020-12-15 ⋅ Trend Micro ⋅ William Gamazo Sanchez
Who is the Threat Actor Behind Operation Earth Kitsune?
Freenki Loader SLUB Earth Kitsune
2020-12-08 ⋅ ⋅ AhnLab ⋅ AhnLab ASEC Analysis Team
“「2021 평화∙통일 이야기 공모전」 참가 신청서” 제목의 한글문서 유포 (APT 추정)
PoorWeb
2020-11-16 ⋅ ReversingLabs ⋅ Robert Simmons
PoorWeb - Hitching a Ride on Hangul
PoorWeb
2020-08-14 ⋅ Department of Homeland Security ⋅ US-CERT
Alert (AA20-227A): Phishing Emails Used to Deploy KONNI Malware
Konni
2020-06-16 ⋅ IBM ⋅ IBM Security X-Force® Incident Responseand Intelligence Services (IRIS)
Cloud ThreatLandscape Report 2020
QNAPCrypt RokRAT
2020-05-21 ⋅ PICUS Security ⋅ Süleyman Özarslan
T1055 Process Injection
BlackEnergy Cardinal RAT Downdelph Emotet Kazuar RokRAT SOUNDBITE
2020-03-30 ⋅ Kaspersky SAS ⋅ Seongsu Park
Behind the Mask of ScarCruft
RokRAT
2020-03-04 ⋅ CrowdStrike ⋅ CrowdStrike
2020 CrowdStrike Global Threat Report
MESSAGETAP More_eggs 8.t Dropper Anchor BabyShark BadNews Clop Cobalt Strike CobInt Cobra Carbon System Cutwail DanaBot Dharma DoppelDridex DoppelPaymer Dridex Emotet FlawedAmmyy FriedEx Gandcrab Get2 IcedID ISFB KerrDown LightNeuron LockerGoga Maze MECHANICAL Necurs Nokki Outlook Backdoor Phobos Predator The Thief QakBot REvil RobinHood Ryuk SDBbot Skipper SmokeLoader TerraRecon TerraStealer TerraTV TinyLoader TrickBot Vidar Winnti ANTHROPOID SPIDER APT23 APT31 APT39 APT40 BlackTech BuhTrap Charming Kitten CLOCKWORK SPIDER DOPPEL SPIDER FIN7 Gamaredon Group GOBLIN PANDA MONTY SPIDER MUSTANG PANDA NARWHAL SPIDER NOCTURNAL SPIDER PINCHY SPIDER SALTY SPIDER SCULLY SPIDER SMOKY SPIDER Thrip VENOM SPIDER VICEROY TIGER
2020-03-03 ⋅ PWC UK ⋅ PWC UK
Cyber Threats 2019:A Year in Retrospect
KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle
2020-02-19 ⋅ Lexfo ⋅ Lexfo
The Lazarus Constellation A study on North Korean malware
FastCash AppleJeus BADCALL Bankshot Brambul Dtrack Duuzer DYEPACK ELECTRICFISH HARDRAIN Hermes HOPLIGHT Joanap KEYMARBLE Kimsuky MimiKatz MyDoom NACHOCHEESE NavRAT PowerRatankba RokRAT Sierra(Alfa,Bravo, ...) Volgmer WannaCryptor
2020-01-27 ⋅ CyberInt ⋅ CyberInt
Konni Malware 2019 Campaign
Konni
2020-01-04 ⋅ Medium d-hunter ⋅ Doron Karmi
A Look Into Konni 2019 Campaign
Konni
2019-10-28 ⋅ ⋅ Tencent ⋅ Tencent
Analysis of Suspected Group123 (APT37) Attacks on Chinese and Korean Foreign Traders
Unidentified 067
2019-08-19 ⋅ ⋅ EST Security ⋅ East Security Response Center
Konni APT organization emerges as an attack disguised as Russian document
Konni
2019-08-12 ⋅ Kindred Security ⋅ Kindred Security
An Overview of Public Platform C2’s
HTML5 Encoding LOWBALL Makadocs MiniDuke RogueRobinNET RokRAT
2019-08-01 ⋅ Kaspersky Labs ⋅ GReAT
APT trends report Q2 2019
ZooPark magecart POWERSTATS Chaperone COMpfun EternalPetya FinFisher RAT HawkEye Keylogger HOPLIGHT Microcin NjRAT Olympic Destroyer PLEAD RokRAT Triton Zebrocy
2019-05-13 ⋅ Kaspersky Labs ⋅ GReAT
ScarCruft continues to evolve, introduces Bluetooth harvester
Konni RokRAT UACMe APT37
2019-05-10 ⋅ Fortiguard ⋅ FortiGuard
Activity Summary - Week Ending May 10, 2019
PoorWeb
2019-01-01 ⋅ Council on Foreign Relations ⋅ Cyber Operations Tracker
APT 37
APT37
2019-01-01 ⋅ MITRE ⋅ MITRE ATT&CK
Group description: APT37
APT37
2018-11-16 ⋅ ⋅ Kim Yejun
Return to ROKRAT!! (feat. FAAAA...Sad...)
RokRAT
2018-10-03 ⋅ Intezer ⋅ Jay Rosenberg
APT37: Final1stspy Reaping the FreeMilk
Final1stSpy RokRAT
2018-10-01 ⋅ Palo Alto Networks Unit 42 ⋅ Josh Grunzweig
NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT
Nokki
2018-10-01 ⋅ Bleeping Computer ⋅ Ionut Ilascu
Report Ties North Korean Attacks to New Malware, Linked by Word Macros
APT37
2018-09-27 ⋅ Palo Alto Networks Unit 42 ⋅ Bryan Lee, Josh Grunzweig
New KONNI Malware attacking Eurasia and Southeast Asia
Nokki
2018-07-10 ⋅ Kaspersky Labs ⋅ GReAT
APT Trends Report Q2 2018
LightNeuron PoorWeb
2018-04-05 ⋅ Palo Alto Networks Unit 42 ⋅ Ruchna Nigam
Reaper Group’s Updated Mobile Arsenal
KevDroid
2018-04-02 ⋅ Cisco Talos ⋅ Jungsoo An, Paul Rascagnères, Vitor Ventura, Warren Mercer
Fake AV Investigation Unearths KevDroid, New Android Malware
KevDroid PubNubRAT
2018-02-27 ⋅ VMWare Carbon Black ⋅ Jared Myers
Threat Analysis: ROKRAT Malware
RokRAT
2018-02-21 ⋅ Twitter (@mstoned7) ⋅ CHA Minseok
Tweet on DPRK APT groups
APT37
2018-02-20 ⋅ FireEye ⋅ FireEye
APT37 (Reaper): The Overlooked North Korean Actor
APT37
2018-02-20 ⋅ FireEye ⋅ FireEye
APT37 (REAPER) The Overlooked North Korean Actor
PoorWeb RokRAT APT37
2018-01-16 ⋅ Cisco Talos ⋅ Paul Rascagnères, Warren Mercer
Korea In The Crosshairs
Freenki Loader RokRAT APT37
2018-01-16 ⋅ Cisco Talos ⋅ Jungsoo An, Paul Rascagnères, Warren Mercer
Korea In The Crosshairs
Freenki Loader PoohMilk Loader RokRAT APT37
2017-11-28 ⋅ Cisco ⋅ Jungsoo An, Paul Rascagnères, Warren Mercer
ROKRAT Reloaded
RokRAT
2017-10-05 ⋅ Palo Alto Networks Unit 42 ⋅ Esmid Idrizovic, Juan Cortes
FreeMilk: A Highly Targeted Spear Phishing Campaign
Freenki Loader PoohMilk Loader
2017-10-05 ⋅ Palo Alto Networks Unit 42 ⋅ Esmid Idrizovic, Juan Cortes
FreeMilk: A Highly Targeted Spear Phishing Campaign
APT37
2017-08-15 ⋅ Fortinet ⋅ Jasper Manuel
A Quick Look at a New KONNI RAT Variant
Konni
2017-07-06 ⋅ Cisco Talos ⋅ Paul Rascagnères
New KONNI Campaign References North Korean Missile Capabilities
Konni
2017-07-01 ⋅ vallejo.cc ⋅ vallejocc
Analysis of new variant of Konni RAT
Konni
2017-05-03 ⋅ Cisco Talos ⋅ Paul Rascagnères
KONNI: A Malware Under The Radar For Years
Konni
2017-04-03 ⋅ Cisco Talos ⋅ Matthew Molyett, Paul Rascagnères, Warren Mercer
Introducing ROKRAT
RokRAT
2017-01-01 ⋅ Cisco Talos ⋅ Paul Rascagnères, Warren Mercer
Introducing ROKRAT
RokRAT
2016-06-17 ⋅ Kaspersky Labs ⋅ Anton Ivanov, Costin Raiu
Operation Daybreak
StarCruft APT37
2016-06-17 ⋅ Threatpost ⋅ Michael Mimoso
ScarCruft APT Group Used Latest Flash Zero Day in Two Dozen Attacks
APT37
2016-06-14 ⋅ Kaspersky Labs ⋅ Costin Raiu
CVE-2016-4171 – Adobe Flash Zero-day used in targeted attacks
APT37

Credits: MISP Project