APT37 (ScarCruft) is a KP-originated cyber espionage group targeting government sectors mainly in South Korea, Japan, and Vietnam.
Analyst brief
APT37 (ScarCruft) is a KP-originated nation-state group active since at least 2012, targeting government and private sectors mainly in South Korea, Japan, and Vietnam. The group typically gains initial access via drive-by compromise (T1189) and malicious files (T1204.002), followed by Python-based execution (T1059.006). Defenders should focus on TTPs like credential theft from web browsers (T1555.003), audio capture (T1123), and steganography (T1027.003) for stealth, as well as the use of known malware such as ROKRAT and Cobalt Strike.
APT37
APT 37Group 123Group123
nation-state
APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its targeting beyond the Korean peninsula to include Japan, Vietnam and the Middle East, and to a wider range of industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive and healthcare entities
origin (suspected)
🇰🇵North Korea· state-sponsoredattribution confidence: medium (50)