All actors

APT37

Also reported as InkySquid, ScarCruft, Reaper, Ricochet Chollima, Group123 and 22 other names. Linked to North Korea by three sources.

Reports
239
Last reported
Known CVEs
255
Techniques in ATT&CK
29
Origin
North Korea
ID
G0067
Merge evidence
33 alias matches

Reports per quarter

  1. 2016 Q2: 8 reports
  2. 2016 Q3: no reports
  3. 2016 Q4: 2 reports
  4. 2017 Q1: 1 report
  5. 2017 Q2: 3 reports
  6. 2017 Q3: 4 reports
  7. 2017 Q4: 2 reports
  8. 2018 Q1: 12 reports
  9. 2018 Q2: 9 reports
  10. 2018 Q3: 6 reports
  11. 2018 Q4: 10 reports
  12. 2019 Q1: 4 reports
  13. 2019 Q2: 6 reports
  14. 2019 Q3: 5 reports
  15. 2019 Q4: 9 reports
  16. 2020 Q1: 11 reports
  17. 2020 Q2: 4 reports
  18. 2020 Q3: 2 reports
  19. 2020 Q4: 10 reports
  20. 2021 Q1: 5 reports
  21. 2021 Q2: 4 reports
  22. 2021 Q3: 13 reports
  23. 2021 Q4: 5 reports
  24. 2022 Q1: 4 reports
  25. 2022 Q2: 7 reports
  26. 2022 Q3: 7 reports
  27. 2022 Q4: 6 reports
  28. 2023 Q1: 17 reports
  29. 2023 Q2: 5 reports
  30. 2023 Q3: 4 reports
  31. 2023 Q4: 6 reports
  32. 2024 Q1: 3 reports
  33. 2024 Q2: 2 reports
  34. 2024 Q3: no reports
  35. 2024 Q4: 3 reports
  36. 2025 Q1: 3 reports
  37. 2025 Q2: 4 reports
  38. 2025 Q3: 2 reports
  39. 2025 Q4: 3 reports
  40. 2026 Q1: no reports
  41. 2026 Q2: 28 reports
Dated reports, 2016 Q2 to 2026 Q2.

Techniques seen in the last two years

Show all 79 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 13 techniques Show fewer

CVEs named in reports

Show all 255 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

Show all 239 reports Show fewer
  1. RokRAT (Malware Family)

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  3. Reaper, APT 37, Ricochet Chollima, ScarCruft

    date ORKL added it fromORKL

  4. Chain Reaction- RokRAT's Missing Link

    date in the title fromORKL

  5. APT37 | ThreatLabz

    Malpedia library date Zscaler fromORKLCCS '25 data

  6. Peeking at Reaper’s surveillance operations

    date in the title fromORKL

  7. HWP Malware Using the Steganography Technique: RedEyes (ScarCruft)

    date in the CCS '25 data AhnLab fromORKLCCS '25 data

  8. Internet Explorer 0-day exploited by North Korean actor APT37

    date in the CCS '25 data Google fromORKLCCS '25 data

  9. Revealing Europe's NSO

    date in the title fromORKL

  10. PowerPoint Presentation

    file creation date fromORKL

  11. Lookout Uncovers Android Spyware Deployed in Kazakhstan

    date in the title fromORKL

  12. The Hermit Kingdom’s Ransomware play

    date in the title fromORKL

  13. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  14. The ink-stained trail of GOLDBACKDOOR

    date in the CCS '25 data stairwell fromORKLCCS '25 data

  15. APT37 Using a New Android Spyware, Chinotto

    date in the title fromORKL

  16. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  17. APT_trends_report_Q2_2021_Securelist

    file creation date fromORKL

  18. North Korean Cyberattacks A Dangerous and Evolving Threat 2

    date in the CCS '25 data Heritage.org fromORKLCCS '25 data

  19. volexity.com-North Korean BLUELIGHT Special InkySquid Deploys RokRAT

    date in the CCS '25 data Volexity fromORKLCCS '25 data

  20. North Korean BLUELIGHT Special- InkySquid Deploys RokRAT

    date in the title fromORKL

  21. volexity.com-North Korean APT InkySquid Infects Victims Using Browser Exploits

    date in the CCS '25 data Volexity fromORKLCCS '25 data

  22. mtrends-2021

    file creation date fromORKL

  23. Analytics

    Malpedia library date fromORKL

  24. Lazarus APT37 IOCs

    date in the CCS '25 data Github (hvs-consulting) fromCCS '25 data

  25. Greetings from Lazarus

    Malpedia library date HvS-Consulting AG fromORKL

  26. Who is the Threat Actor Behind Operation Earth Kitsune-

    date in the title fromORKL

  27. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  28. APT_trends_report_Q3_2020_Securelist

    file creation date fromORKL

  29. APT trends report Q3 2020

    date in the title fromORKL

  30. The many personalities of Lazarus

    date in the title fromORKL

  31. Cloud Threat Landscape Report 2020,pdf

    date in the title fromORKL

  32. T1055 Process Injection

    date in the title fromORKL

  33. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  34. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  35. Lexfo-WhitePaper-The_Lazarus_Constellation

    file creation date fromORKL

  36. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  37. sadasd

    Malpedia library date fromORKL

  38. Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  39. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  40. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  41. APT Trends Report Q2 2018

    file creation date Kaspersky fromORKL

  42. mobile-malware-report.pdf

    file creation date fromORKL

  43. (cn)_higaisa_apt_report

    file creation date fromORKL

  44. APT_trends_report_Q2_2019_Securelist

    file creation date fromORKL

  45. APT trends report Q2 2019

    date in the title fromORKL

  46. ScarCruft continues to evolve, introduces Bluetooth harvester _ Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  47. rpt-mtrends-2019.pdf

    file creation date fromORKL

  48. rpt-mtrends-2019

    file creation date fromORKL

  49. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  50. 2018 APT Summary Report CN version

    file creation date fromORKL

  51. Return to ROKRAT!! (feat. FAAAA...Sad...)

    date in the title fromORKL

  52. APT37- Final1stspy Reaping the FreeMilk

    date in the title fromORKL

  53. rpt-apt38-2018-web_v4

    file creation date fromORKL

  54. APT37 Final1stspy Reaping the FreeMilk

    date in the CCS '25 data Intezer fromCCS '25 data

  55. OPERATION "Rocket Man"

    date in the CCS '25 data ESTSecurity fromORKLCCS '25 data

  56. Operation Daybreak

    file creation date Kaspersky fromORKL

  57. APT Trends Report Q2 2018

    date in the title fromORKL

  58. Red_Eyes_Hacking_Group_Report

    date in the CCS '25 data ggunyong fromORKLCCS '25 data

  59. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  60. APT Trends report Q1 2018

    date in the title fromORKL

  61. Reaper Group’s Updated Mobile Arsenal

    date in the title fromORKL

  62. Tech_Report_Malicious_Hancom

    date in the CCS '25 data AhnLab fromORKLCCS '25 data

  63. APT37.blog

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  64. APT37 (Reaper)- The Overlooked North Korean Actor

    date in the title fromORKL

  65. rpt_APT37.pdf

    Malpedia library date fromORKL

  66. APT37 (Reaper): The Overlooked North Korean Actor

    date in the CCS '25 data FireEye fromCCS '25 data

  67. APT37 (Reaper): The Overlooked North Korean Actor

    file creation date FireEye fromORKL

  68. Korea In The Crosshairs

    date in the title fromORKL

  69. Cisco's Talos Intelligence Group Blog: Korea In The Crosshairs

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  70. Talos_RokRatWhitePaper.pdf

    file creation date fromORKL

  71. Microsoft_Security_Intelligence_Report_Volume_21_English

    file creation date fromORKL

  72. Operation Daybreak

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  73. Operation Daybreak

    date in the title fromORKL

Newest first. Details opens the report in Explore.