Overview 494 indicators
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
| domain | 436 | G0067-domain.txt |
| url | 47 | G0067.json |
| url_path | 9 | G0067.json |
| ipv4 | 2 | G0067.json |
Techniques 29 ATT&CK
Open in ATT&CK Navigator → or download the layer (29 techniques, layer 4.5)
- T1005 Data from Local System
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1033 System Owner/User Discovery
- T1036.001 Invalid Code Signature
- T1053.005 Scheduled Task
- T1055 Process Injection
- T1057 Process Discovery
- T1059 Command and Scripting Interpreter
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.006 Python
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1120 Peripheral Device Discovery
- T1123 Audio Capture
- T1189 Drive-by Compromise
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1529 System Shutdown/Reboot
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1555.003 Credentials from Web Browsers
- T1559.002 Dynamic Data Exchange
- T1561.002 Disk Structure Wipe
- T1566.001 Spearphishing Attachment
Software 13
- Cobalt Strike
- CORALDECK
- DOGCALL
- HAPPYWORK
- KARAE
- POORAIM
- SHUTTERSPEED
- SLOWDRIFT
- WINERACK
- ROKRAT
- NavRAT
- Final1stspy
- BLUELIGHT
Principal sources 178 reports
Ranked by how many of this actor's indicators each report brought in.
- 139github.com/EmergingThreats/threatresearch/blob/mas…
- 77bloomberglaw.com/document/public/subdoc/X67FPNDOUBV9VOPS…
- 77malpedia.caad.fkie.fraunhofer.de/actor/apt37
- 77twitter.com/jfslowik/status/1212097943550873600
- 77x.com/TIntel2255/status/1840825662925652152
- 77otx.alienvault.com/pulse/5e0b9895c5ed003a85210202 (# Thall…
- 77pastebin.com/ScaPd18W
- 37sentinelone.com/labs/a-glimpse-into-future-scarcruft-ca…
Related groups 6
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 494 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 494. Complete: G0067.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/rst_cloud/status/2069838671763640509 · genians.co.kr/en/blog/threat_intelligence/narwhalrat
crwellfood.com daehoat.com fe01.co.kr novel21.co.kr -
welivesecurity.com/en/eset-research/rigged-game-scarcruft-… · github.com/eset/malware-ioc/tree/master/scarcruft#…
1980food.co.kr cndsoft.co.kr colorncopy.co.kr lawwell.co.kr sejonghaeun.com sqgame.com.cn swr.co.kr xiazai.sqgame.com.cn -
genians.co.kr/en/blog/threat_intelligence/pretexting · virustotal.com/gui/file/3ecb8632582982f5ea4cef6b32ac46…
japanroom.com -
zscaler.com/blogs/security-research/apt37-adds-new-… · virustotal.com/gui/file/a8b8a92d170029885d4e7763675f10… · virustotal.com/gui/file/c61c679eec1c1b43bbd01727fdfb6a…
domain hightkdhe.store domain homeatedke.store domain philion.store ipv4 144.172.106.66:8080 -
x.com/Cyberteam008/status/1940265872402403341
admin.primgs.lol grip-cdns.space img.responsive.pstatic.autos img.smartnords.site img.worksongo.store primgs.lol pstatic.autos responsive.pstatic.autos show.grip-cdns.space smartnords.site worksongo.store -
x.com/volrant136/status/1944429848807530870
app.cleanos.online cleanos.online darklights.store img.darklights.store img.monderhouse.space img.socialteams.store monderhouse.space socialteams.store -
x.com/byrne_emmy12099/status/1951675987198173… · seqrite.com/blog/operation-hankook-phantom-north-ko… · virustotal.com/gui/file/d8d86b15e68889bf76b3cf8e335f43…
daily.alltop.asia/blog/article/d2.php daily.alltop.asia/blog/article/del2.php daily.alltop.asia/blog/article/up2.php -
x.com/SwitHak/status/1922259600113328605 · proofpoint.com/us/blog/threat-insight/ta406-pivots-fro…
pokijhgcfsdfghnj.mywebcommunity.org qweasdzxc.mygamesonline.org wersdfxcv.mygamesonline.org -
x.com/suyog41/status/1995767452786196839 · virustotal.com/gui/file/4f2617a971b9c78c8b215d6cb65525…
jlrandsons.co.uk -
x.com/lazarusholic/status/1947650364825866590 · asec.ahnlab.com/ko/89116 · virustotal.com/gui/file/e27467f7fdfa721e917384542ce10c… · virustotal.com/gui/file/41d9b6d8cf0fff85bf35327d4b94db… · virustotal.com/gui/file/6a2d984ef3fa0de9b9feb5f5583812…
uploader10klg.disk.yandex.net -
x.com/Threatlabz/status/1965060646405574786 · zscaler.com/blogs/security-research/apt37-targets-w… · virustotal.com/gui/file/738a31e7a0d96fe1b0ad6778db3942…
hnkoaa.co.kr/files/2023/12/01/win.php -
x.com/blackorbird/status/1886245222923091975 · genians.co.kr/blog/threat_intelligence/k-messenger
imagedownloadsupport.com mailattachmentimageurlxyz.site -
x.com/byrne_emmy12099/status/1864880849277325… · virustotal.com/gui/file/d9e3eba6067eec0aa32214b2a9811f…
uploader1j.disk.yandex.net uploader77j.disk.yandex.net -
genians.co.kr/blog/threat_intelligence/apt37_recon
filedownloadserve.com kakaofilestorage.com navarar.com -
x.com/the_yellow_fall/status/1846484897495699… · x.com/k3yp0d/status/1848277967387963582 · virustotal.com/gui/ip-address/84.32.131.214/relations · securityonline.info/north-korean-hackers-exploit-zero-day-f…
admin.mobonad.com img.mobonad.com mobonad.com -
x.com/blackorbird/status/1846828667718234555 · medium.com/s2wblog/unmasking-cve-2024-38178-the-si…
domain js.ad4949.co.kr url mini.gomlab.com/player/html/toast/toast_KR_N.html -
bloomberglaw.com/document/public/subdoc/X67FPNDOUBV9VOPS… · malpedia.caad.fkie.fraunhofer.de/actor/apt37 · twitter.com/jfslowik/status/1212097943550873600 · x.com/TIntel2255/status/1840825662925652152 · otx.alienvault.com/pulse/5e0b9895c5ed003a85210202 (# Thall… · pastebin.com/ScaPd18W
http-accounts.maingoogie.com https-accounts.maingoogie.com -
x.com/JAMESWT_MHT/status/1836784273191297442 · x.com/JAMESWT_MHT/status/1836847390638362767 · virustotal.com/gui/file/9d0807210b0615870545a18ab8eae8… · virustotal.com/gui/file/133359336ed60b94e9cd500fb518a7…
ipv4 208.85.16.88:5555 url http://208.85.16.88 -
twitter.com/h2jazi/status/1699821987361702229 · x.com/malwrhunterteam/status/1814396386521260… · github.com/Cisco-Talos/IOCs/blob/main/2023/11/new-… · github.com/Cisco-Talos/IOCs/blob/main/2024/06/snea… · virustotal.com/gui/file/7c87451261dfce64fda987eb395694… · virustotal.com/gui/file/d0775ec420a4938cbf1b2e9432677e…
account.gommask.online gommask.online -
x.com/JangPr0/status/1793945744577364344 · virustotal.com/gui/file/2222f1d7ccd05655f0492769bc54ec…
host.sharingdocument.one sharingdocument.one -
twitter.com/suyog41/status/1772149859698524630 · virustotal.com/gui/file/fb55f221a1c382eaaea943c9c4c3bc…
ems.nps.or.kr sklims.lat -
virustotal.com/gui/file/2ede67e3953d9d8519f450c6be70f2…
urbiusla.homes -
sentinelone.com/labs/a-glimpse-into-future-scarcruft-ca…
alireza.traderfree.online bellissues.live benefitinfo.live benefitinfo.pro benefiturl.pro careagency.online cra-receivenow.online crareceive.site depositurl.co depositurl.lat direct.traderfree.online faguo.namecentless.top forex.traderfree.online groceryrebate.online groceryrebate.site gstcreceive.online hl.namecentless.top instantreceive.org li.namecentless.top lin.namecentless.top namecentless.top receive.bio receiveinstant.online rentsubsidy.help rentsubsidy.online shate.namecentless.top tes.namecentless.top tes1.namecentless.top tes2.namecentless.top tes3.namecentless.top tes4.namecentless.top tinyurlinstant.co traderfree.online ttt.namecentless.top urldepost.co verifyca.online visiononline.store -
twitter.com/fmc_nan/status/1729428966967271693 · virustotal.com/gui/file/194354cae93878dc3ba6ca2f71b704…
goodmarket.or.kr -
twitter.com/StopMalvertisin/status/1722227919634981… · virustotal.com/gui/file/7387d00194adf8a8f15e12e191bfaa…
ebpp.airport.kr -
twitter.com/blackorbird/status/1714576304279032023 · github.com/blackorbird/APT_REPORT/blob/master/kims…
cheth.lol honess.fun plifty.lat sgibn.cam -
twitter.com/suyog41/status/1704025925187473638 · twitter.com/suyog41/status/1704098124762132790 · virustotal.com/gui/file/02489e283a347299152394ca9ef828…
teishin.org/img/Updater.zip teishin.org/treasury/resources/admin/wp-admin/attack.php teishin.org/treasury/wp_asist.php -
twitter.com/h2jazi/status/1699821987361702229 · x.com/malwrhunterteam/status/1814396386521260… · github.com/Cisco-Talos/IOCs/blob/main/2023/11/new-… · github.com/Cisco-Talos/IOCs/blob/main/2024/06/snea… · virustotal.com/gui/file/7c87451261dfce64fda987eb395694… · virustotal.com/gui/file/d0775ec420a4938cbf1b2e9432677e…
account.drive-google-com.tk accounts-youtube.drive-google-com.tk drive-google-com.tk gmail.drive-google-com.tk login.drive-google-com.tk ssl-gstatic.drive-google-com.tk -
twitter.com/suyog41/status/1697536913610314016 · virustotal.com/gui/file/b31b89e646de6e9c5cbe21798e0157…
navercorp.ru -
twitter.com/blackorbird/status/1694912623299674230 · mp.weixin.qq.com/s/pIdyesArvoXaD-lLYVvXiw
bajut.pro giath.xyz oebil.lat -
twitter.com/suyog41/status/1691027132254986240 · virustotal.com/gui/file/ee08d70c66ce95755b6936d59290ec…
nobuay.ink -
twitter.com/StopMalvertisin/status/1690422578509479… · virustotal.com/gui/file/7dd84cc7d8271a88063ce1ff1f1abe…
domain bian0151.cafe24.com domain vmi810830.contaboserver.net url ableinfo.co.kr/member/ url http://75.119.136.207 -
twitter.com/StopMalvertisin/status/1690399430405734… · virustotal.com/gui/file/f5e46e18facc6f8fde6658b96dcd37… · virustotal.com/gui/file/fcfb0398eb0216332bb3ce25e5e353…
crilts.cfd labimy.ink -
twitter.com/StopMalvertisin/status/1690399427255758… · virustotal.com/gui/file/5071a29f42689c6d83de6fc16bbc62…
drimby.top -
twitter.com/h2jazi/status/1688977725279600648 · virustotal.com/gui/file/d42ef12b6b40c1e3d0132a4be8954b…
jutise.fun -
twitter.com/malwrhunterteam/status/1681595936991064… · virustotal.com/gui/file/eb21cf8e6f64340216e9c326fb5895…
domain ppangz.mom url_path /mjifi -
twitter.com/h2jazi/status/1681122432000618499 · virustotal.com/gui/file/012063e0b7b4f7f3ce50574797112f… · virustotal.com/gui/file/01e7405ddd5545ffb4a57040acc4b6…
atusay.lat tosals.ink -
twitter.com/fmc_nan/status/1664179152331866112 · virustotal.com/gui/file/c26746a7a3e474e2c4915b4e05042a…
http://172.93.181.249 -
twitter.com/StopMalvertisin/status/1662733487768739…
http://128.199.133.121 -
community.emergingthreats.net/t/ruleset-update-summary-2023-05-01-v10…
daum-store.com docx1.b4a.app link.b4a.app nate-download.com naver-file.com naver-storage.com -
twitter.com/malwrhunterteam/status/1646612420683526… · virustotal.com/gui/ip-address/194.165.16.93/relations · virustotal.com/gui/file/1f3d808d89ea6c78d0fb0ff7e7d4be…
sharefiles-betterbusinessbureau-upload.com sharefiles-betterbusinessbureau-us1.com -
twitter.com/fmc_nan/status/1638528180947668993 · twitter.com/malwrhunterteam/status/1638661235146104… · virustotal.com/gui/file/40cb1016a2d962482f40f1ce712403…
yangak.com/data/cheditor4/pro/ yangak.com/data/cheditor4/pro/mid.php -
twitter.com/fmc_nan/status/1638528180947668993 · twitter.com/malwrhunterteam/status/1638661235146104… · virustotal.com/gui/file/40cb1016a2d962482f40f1ce712403…
yangak.com/data/cheditor4/pro/temp/7.html -
blog.sekoia.io/peeking-at-reaper-surveillance-operatio…
attiferstudio.com/install.bak/sony/ clovery-shapes.000webhostapp.com/defcon/ hk-law.co.kr/data/file/joomla/ http://141.105.65.165 jdwanxiang.com/win/shenti/ koaagj.co.kr/files/2014/12/fix/ ri-guard.com/download/temp/cn-var/ -
asec-ahnlab-com.translate.goog/ko/48764/?_x_tr_sl=auto&_x_tr_tl=es&_x_… · otx.alienvault.com/pulse/6408a4922f014d07a51f1f77
shacc.kr/skin/product/mid.xn--php -
asec.ahnlab.com/en/48063 · otx.alienvault.com/pulse/63f67cceee1cc80ed9497ecf
elearning.or.kr -
github.com/blackorbird/APT_REPORT/blob/master/kims… · virustotal.com/gui/file/fd25c643565fdd42bb9a9af7d965b2…
shoru.net -
github.com/blackorbird/APT_REPORT/blob/master/grou…
/bbs/data/cjdc/proc.php /bbs/data/comb/price.php -
twitter.com/Timele9527/status/1600690222685032448 · blog.google/threat-analysis-group/internet-explorer…
free-xmlformat.com ms-office.services openxmlformat.org template-openxml.com word-template.net -
cib.gov.tw/News/BulletinDetail/8294 · otx.alienvault.com/pulse/5ec7ff4ec67d6aca23b7c350 · virustotal.com/gui/file/926a947ea2b59d3e9a5a6875b4de2b… · virustotal.com/gui/file/af5fb99d3ff18bc625fb63f792ed7c…
conference.outlook-offices.com file-sharing.tibet-office.com file.outlook-offices.com mofa.outlook-offices.com nds1.outlook-offices.com office.phonectrl.com -
twitter.com/Timele9527/status/1600690222685032448 · blog.google/threat-analysis-group/internet-explorer…
ms-offices.com -
otx.alienvault.com/pulse/62e127f6ae973b499899ff9b · virustotal.com/gui/file/0675443b6438e3a7e910d591aaefcf…
http://185.176.43.106 -
twitter.com/malwrhunterteam/status/1523754342402052… · virustotal.com/gui/file/ce1a5653444eb9902dd98365b1e2fd… · github.com/blackorbird/APT_REPORT/blob/master/kims…
cerebrovascular.net -
stairwell.com/wp-content/uploads/2022/04/Stairwell-th… · lists.emergingthreats.net/pipermail/emerging-sigs/2022-April/0306… · otx.alienvault.com/pulse/6261887e15fc527fe850e657
lit-peak-25706.herokuapp.com -
stairwell.com/wp-content/uploads/2022/04/Stairwell-th… · lists.emergingthreats.net/pipermail/emerging-sigs/2022-April/0306… · otx.alienvault.com/pulse/6261887e15fc527fe850e657
dailynk.us mail.dailynk.us main.dailynk.us -
proofpoint.com/sites/default/files/threat-reports/pfpt… · otx.alienvault.com/pulse/61978976fed1a4a1794586e7
acl-medias.fr christinadudley.com fd-com.fr influencer.jvproduccionessv.com kswebdesign.eu mail.apm.co.kr mail.summitz.com oaass.co.kr rabadaun.com simple.kswebdesign.eu -
twitter.com/malwrhunterteam/status/1510919695423184… · virustotal.com/gui/file/e6091e6bf8135e09f46b6a230873a6… · virustotal.com/gui/file/e4ff04fe1aa1f28a993ac57cac277c… · github.com/blackorbird/APT_REPORT/blob/master/kims…
successgoo.com vhostnetwork.com -
volexity.com/blog/2021/08/17/north-korean-apt-inkysq… · otx.alienvault.com/pulse/611ce45950765f93f688ba00
domain api.jquery.services domain cdns.jquery.services domain gallery.jquery.services domain image.jquery.services domain jquery.services domain module.jquery.services domain slider.jquery.services domain stock.jquery.services domain storage.jquery.services domain svg.jquery.services domain table.jquery.services domain treeview.jquery.services domain ui.jquery.services url dailynk.com/wp-includes/js/jquery/jquery-migrate.min.js url dailynk.com/wp-includes/js/jquery/jquery.min.js -
twitter.com/cyberwar_15/status/1481430358629707776 · twitter.com/cyberwar_15/status/1528619208183287809 · twitter.com/ShadowChasing1/status/15294519945321676…
bigfilemail.net work3.b4a.app -
virustotal.com/gui/file/facb0525447439cb402c1808e5a3a2… · virustotal.com/gui/file/81973e40fdb988d38342c901f334c4… · virustotal.com/gui/file/3a68d6bceb126fa26fa3549ccc8ac1…
/bbs/pu.php?do=upload -
twitter.com/midnight_comms/status/14678870935610531… · virustotal.com/gui/file/facb0525447439cb402c1808e5a3a2… · virustotal.com/gui/file/81973e40fdb988d38342c901f334c4… · virustotal.com/gui/file/3a68d6bceb126fa26fa3549ccc8ac1…
iblcor.cafe24.com -
twitter.com/midnight_comms/status/14678868702269521… · virustotal.com/gui/file/3f3d492fe284569abb0ee60595e63c…
annstyle.ru -
0xthreatintel.medium.com/apt37-targets-journalists-security-rese…
js5950.cafe24.com kjdnc.gp114.net -
securelist.com/scarcruft-surveilling-north-korean-defe…
djsm.co.kr/js/20170805.hwp doseoul.com/bbs/data/hnc/update.php haeundaejugong.com/data/jugong/do.php haeundaejugong.com/editor/chinotto/do.php kjdnc.gp114.net/data/log/do.php kumdo.org/admin/cont/do.php luminix.kr/bbs/data/proc/proc.php luminix.openhaja.com/bbs/data/proc1/proc.php -
github.com/EmergingThreats/threatresearch/blob/mas…
0member-services.hol.es 1006ieudneu.atwebpages.com 1995ieudneu.atwebpages.com acount-pro.club acount-pro.live anlysis-info.xyz attachdown.000webhostapp.com attachdownload.000webhostapp.com attachdownload.99on.com carnegieinsider.com clonesec.us cloudocument.com daumhelp.net deioncube.biz diplomatictraining.com dnsservice.esy.es document-package.online documentpackage.space documentpackages.link documentpackages.online documentpackages.space documentpackages.store download-apks.com download-live.com emailnaver.com emailru.99on.com globalcloudservices.org gooapi.online google-acount.com goolg-e.com goolge.space govermentweb.site help-master.online help-naver.site help-secure.info helpnaver.host helpnaver.link helpnaver.online helpnaver.site hpronto-login.com knowledgeofworld.org koryogroup.1apps.com login-protect.club login-protect.online mail-master.online microsoft-pro.host microsoft-pro.live microsoft-pro.site microsoft-pro.space mid-service.com mid-service.org myethrvvallet.com mysoftazure.com naverhelp.com navermain.com nicnaver.com nidnaver.host nidnaver.press nidnaver.site nidnaver.store noreply-cc.online noreply-goolge.com noreply-sec.online noreply-yahoo.com north-korea.medianewsonline.com online-manual.c1.biz proattachfile.com rfa.news rnail-suport.site secureaction.ru securelevel.site security-nid.space security-pro.me security-pro.online securityforcastreport.com securitysettings.info silverlog.hol.es sinoforecast.com · 18 more in this batch, in the JSON
Further reading 183
- attack.mitre.org/groups/G0067
- blog.talosintelligence.com/2018/01/korea-in-crosshairs.html
- securelist.com/operation-daybreak/75100
- securelist.com/scarcruft-continues-to-evolve-introduce…
- services.google.com/fh/files/misc/apt37-reaper-the-overlook…
- crowdstrike.com/adversaries/ricochet-chollima
- volexity.com/blog/2021/08/17/north-korean-apt-inkysq…
- twitter.com/ShadowChasing1/status/15294519945321676…
- virustotal.com/gui/file/012063e0b7b4f7f3ce50574797112f…
- genians.co.kr/en/blog/threat_intelligence/narwhalrat
- x.com/Threatlabz/status/1965060646405574786
- twitter.com/blackorbird/status/1694912623299674230
- twitter.com/blackorbird/status/1188726162928758784
- x.com/rst_cloud/status/2069838671763640509
- securelist.com/scarcruft-surveilling-north-korean-defe…
- virustotal.com/gui/file/fd25c643565fdd42bb9a9af7d965b2…
- twitter.com/cyberwar_15/status/1392488563309105155
- virustotal.com/gui/file/738a31e7a0d96fe1b0ad6778db3942…
- virustotal.com/gui/file/eb21cf8e6f64340216e9c326fb5895…
- twitter.com/malwrhunterteam/status/1681595936991064…
- twitter.com/h2jazi/status/1699821987361702229
- virustotal.com/gui/file/3f3d492fe284569abb0ee60595e63c…
- virustotal.com/gui/file/194354cae93878dc3ba6ca2f71b704…
- asec.ahnlab.com/en/48063
- github.com/Cisco-Talos/IOCs/blob/main/2024/06/snea…
- virustotal.com/gui/file/7820bc1aa19ed61d035a2b7efb315d…
- twitter.com/cyberwar_15/status/1422376991907450886
- twitter.com/midnight_comms/status/14678870935610531…
- virustotal.com/gui/file/7dd84cc7d8271a88063ce1ff1f1abe…
- virustotal.com/gui/file/d9e3eba6067eec0aa32214b2a9811f…
- x.com/JangPr0/status/1793945744577364344
- twitter.com/navSi16/status/1066296138498629637
- twitter.com/kyleehmke/status/1217486993871056899
- virustotal.com/gui/ip-address/23.106.160.32/relations
- twitter.com/h2jazi/status/1681122432000618499
- x.com/malwrhunterteam/status/1814396386521260…
- 0xthreatintel.medium.com/apt37-targets-journalists-security-rese…
- x.com/suyog41/status/1995767452786196839
- x.com/the_yellow_fall/status/1846484897495699…
- twitter.com/fmc_nan/status/1638528180947668993
143 more, and the report behind every indicator, in G0067.json.