Threat actor · all actors
APT37G0067 state
🇰🇵 KP
aka APT37, InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, APT 37, Group 123, Operation Daybreak, Operation Erebus, Reaper Group, Red Eyes, Venus 121, ATK4, G0067, Moldy Pisces, APT-C-28, PLAIN NEPTUNE
Last updated: 2026-08-20
About this actor
[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. [APT37](https://attack.mitre.org/groups/G0067) has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
MandiantTEMP temporary cluster
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 40 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2016 — 1 CVE published
- 2015 — 1 CVE published
- 2014 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2015-3105 | 8.0 | 0.0 | 0.9732 | 2015-06-10 | see CVE |
CVE-2016-0147 | 8.0 | 8.8 | 0.2642 | 2016-04-12 | see CVE |
CVE-2013-4979 | 6.0 | 0.0 | 0.1171 | 2014-01-31 | see CVE |
CVE-2013-0808 | 0.0 | 0.0 | 0.0000 | see CVE |
T1005Data from Local System ↗T1027Obfuscated Files or Information ↗T1027.003Steganography ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.001Invalid Code Signature ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1059.006Python ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1082System Information Discovery ↗T1102Web Service ↗T1102.002Bidirectional Communication ↗T1105Ingress Tool Transfer ↗T1106Native API ↗T1120Peripheral Device Discovery ↗T1123Audio Capture ↗T1189Drive-by Compromise ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.002Malicious File ↗T1529System Shutdown/Reboot ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1548Abuse Elevation Control Mechanism ↗T1548.002Bypass User Account Control ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1559Inter-Process Communication ↗T1559.002Dynamic Data Exchange ↗T1561Disk Wipe ↗T1561.002Disk Structure Wipe ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 30 / 40 | 75% |
CM-2 | 26 / 40 | 65% |
CM-6 | 25 / 40 | 62% |
SI-3 | 25 / 40 | 62% |
AC-6 | 19 / 40 | 48% |
CM-7 | 17 / 40 | 42% |
AC-3 | 16 / 40 | 40% |
CA-7 | 16 / 40 | 40% |
SI-2 | 16 / 40 | 40% |
SC-7 | 14 / 40 | 35% |
SI-7 | 14 / 40 | 35% |
AC-4 | 13 / 40 | 32% |
AC-2 | 12 / 40 | 30% |
CM-8 | 9 / 40 | 22% |
RA-5 | 9 / 40 | 22% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Windshift 0.39
- Patchwork 0.36
- BRONZE BUTLER 0.32
- Inception 0.32
- Frankenstein 0.32
Active in same years
- 2016 Ukraine Electric Power Attack 1.00
- 2015 Ukraine Electric Power Attack 1.00
- NEODYMIUM 1.00
- PROMETHIUM 1.00
- APT38 1.00
Same nation-state
- Operation Dream Job 1.00
- 3CX Supply Chain Attack 1.00
- Lazarus Group 1.00
- APT38 1.00
- Kimsuky 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00