APT37
Also reported as InkySquid, ScarCruft, Reaper, Ricochet Chollima, Group123 and 22 other names. Linked to North Korea by three sources.
Reports per quarter
Techniques seen in the last two years
- T1566.001 4 reports in ATT&CK
- T1041 2 reports reports only
- T1059.001 2 reports reports only
- T1070.004 2 reports reports only
- T1082 2 reports in ATT&CK
- T1091 2 reports reports only
- T1112 2 reports reports only
- T1189 2 reports in ATT&CK
- T1190 2 reports reports only
- T1204.002 2 reports in ATT&CK
Show all 79 techniques Show fewer
- T1555 2 reports reports only
- T1560 2 reports reports only
- T1566.002 2 reports reports only
- T1584.004 2 reports reports only
- T1659 2 reports reports only
- T1003 1 report reports only
- T1005 1 report in ATT&CK
- T1020 1 report reports only
- T1027 1 report in ATT&CK
- T1027.013 1 report reports only
- T1033 1 report in ATT&CK
- T1046 1 report reports only
- T1053 1 report reports only
- T1053.005 1 report in ATT&CK
- T1055 1 report in ATT&CK
- T1056.001 1 report reports only
- T1057 1 report in ATT&CK
- T1059 1 report in ATT&CK
- T1059.003 1 report in ATT&CK
- T1059.007 1 report reports only
- T1069 1 report reports only
- T1071.001 1 report in ATT&CK
- T1083 1 report reports only
- T1090 1 report reports only
- T1102.002 1 report in ATT&CK
- T1105 1 report in ATT&CK
- T1113 1 report reports only
- T1115 1 report reports only
- T1119 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1140 1 report reports only
- T1195 1 report reports only
- T1195.002 1 report reports only
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1212 1 report reports only
- T1406 1 report reports only
- T1407 1 report reports only
- T1420 1 report reports only
- T1422 1 report reports only
- T1426 1 report reports only
- T1429 1 report reports only
- T1430 1 report reports only
- T1437.001 1 report reports only
- T1474.003 1 report reports only
- T1480.001 1 report reports only
- T1481.002 1 report reports only
- T1497 1 report reports only
- T1513 1 report reports only
- T1532 1 report reports only
- T1533 1 report reports only
- T1541 1 report reports only
- T1546.015 1 report reports only
- T1547.001 1 report in ATT&CK
- T1566 1 report reports only
- T1566.003 1 report reports only
- T1567 1 report reports only
- T1567.002 1 report reports only
- T1571 1 report reports only
- T1573.001 1 report reports only
- T1574.014 1 report reports only
- T1585.003 1 report reports only
- T1587.001 1 report reports only
- T1608.001 1 report reports only
- T1636.002 1 report reports only
- T1636.003 1 report reports only
- T1636.004 1 report reports only
- T1646 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
Show all 13 techniques Show fewer
CVEs named in reports
- CVE-2008-2551
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-0840 KEV
- CVE-2010-1297 KEV
- CVE-2010-2568 KEV
- CVE-2010-3333 KEV
- CVE-2010-3336
- CVE-2010-3653
Show all 255 CVEs Show fewer
- CVE-2010-4398 KEV
- CVE-2011-0097
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-1823 KEV
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0056
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0507 KEV ransomware
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2423 KEV
- CVE-2013-2460
- CVE-2013-2551 KEV ransomware
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3896 KEV
- CVE-2013-3897 KEV
- CVE-2013-3900 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-7331 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4076
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8439 KEV
- CVE-2015-0072
- CVE-2015-0310 KEV
- CVE-2015-0311 KEV
- CVE-2015-0313 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1671 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3090
- CVE-2015-3105
- CVE-2015-3636
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0165 KEV
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-3393 KEV
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9805 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-15133 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4876
- CVE-2018-4878 KEV ransomware
- CVE-2018-4990 KEV
- CVE-2018-5002 KEV
- CVE-2018-6055
- CVE-2018-7445 KEV
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8242
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8414 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0803 KEV ransomware
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-7609 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-17144 KEV
- CVE-2020-27937
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-9771
- CVE-2020-9934 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-21972 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-28550 KEV
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-31199 KEV
- CVE-2021-31201 KEV
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34480
- CVE-2021-34527 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-36948 KEV
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0609 KEV
- CVE-2022-1040 KEV
- CVE-2022-20821 KEV
- CVE-2022-22047 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-26871 KEV
- CVE-2022-27518 KEV
- CVE-2022-27926 KEV
- CVE-2022-28810 KEV
- CVE-2022-29499 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-33891 KEV
- CVE-2022-40139 KEV
- CVE-2022-41040 KEV ransomware
- CVE-2022-41128 KEV
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-44698 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-24880 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-21413 KEV
- CVE-2024-26229
- CVE-2024-38178 KEV
- CVE-2024-42009 KEV
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2024-9680 KEV ransomware
- CVE-2025-0282 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-1281 KEV
- CVE-2026-1340 KEV
- CVE-2026-21509 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Return of the mac(OS): Transparency, Consent, and Control (TCC) Database Manipulation - Interpres Security
Show all 239 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor RokRAT (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Reaper, APT 37, Ricochet Chollima, ScarCruft
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Reaper, APT 37, Ricochet Chollima, ScarCruft
-
Chain Reaction- RokRAT's Missing Link
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chain Reaction- RokRAT's Missing Link
-
RokRAT Malware Distributed Through LNK Files (.lnk)- RedEyes (ScarCruft)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor RokRAT Malware Distributed Through LNK Files (.lnk)- RedEyes (ScarCruft)
-
202304114e0fa0f4fd1d408aaddeef8be63a4757_20230411161526_0531.pdf
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor 202304114e0fa0f4fd1d408aaddeef8be63a4757_20230411161526_0531.pdf
-
Chinotto Backdoor Technical Analysis of the APT Reaper’s Powerful Weapon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinotto Backdoor Technical Analysis of the APT Reaper’s Powerful Weapon
-
Kimsuky group distributes malware disguised as a profile file (GitHub)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky group distributes malware disguised as a profile file (GitHub)
-
Scarcruft Bolsters Arsenal for targeting individual Android devices
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Scarcruft Bolsters Arsenal for targeting individual Android devices
-
Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
-
Peeking at Reaper’s surveillance operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Peeking at Reaper’s surveillance operations
-
Magniber ransomware actors used a variant of Microsoft SmartScreen bypass
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Magniber ransomware actors used a variant of Microsoft SmartScreen bypass
-
HWP Malware Using the Steganography Technique: RedEyes (ScarCruft)
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor HWP Malware Using the Steganography Technique: RedEyes (ScarCruft)
-
WIP26 Espionage - Threat Actors Abuse Cloud Infrastructure in Targeted Telco Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WIP26 Espionage - Threat Actors Abuse Cloud Infrastructure in Targeted Telco Attacks
-
Hangeul (HWP) malware using steganography- RedEyes (ScarCruft)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hangeul (HWP) malware using steganography- RedEyes (ScarCruft)
-
Emulating the Highly Sophisticated North Korean Adversary Lazarus Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emulating the Highly Sophisticated North Korean Adversary Lazarus Group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Report- RambleOn Android Malware - Detailed analysis report of cyber threat targeting journalist in South Korea through APT phishing campaign with malicious APK
-
Internet Explorer 0-day exploited by North Korean actor APT37
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Internet Explorer 0-day exploited by North Korean actor APT37
-
Internet Explorer 0-day exploited by North Korean actor APT37
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Internet Explorer 0-day exploited by North Korean actor APT37
-
Who’s swimming in South Korean waters- Meet ScarCruft’s Dolphin
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who’s swimming in South Korean waters- Meet ScarCruft’s Dolphin
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Revealing Europe's NSO
-
The original link failed its last check. Original publisher Detailsfor PowerPoint Presentation
-
North Korean hackers attack EU targets with Konni RAT malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean hackers attack EU targets with Konni RAT malware
-
Lookout Uncovers Android Spyware Deployed in Kazakhstan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lookout Uncovers Android Spyware Deployed in Kazakhstan
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
The Hermit Kingdom’s Ransomware play
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Hermit Kingdom’s Ransomware play
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The ink-stained trail of GOLDBACKDOOR
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The ink-stained trail of GOLDBACKDOOR
-
Not So Lazarus- Mapping DPRK Cyber Threat Groups to Government Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Not So Lazarus- Mapping DPRK Cyber Threat Groups to Government Organizations
-
Hackers take over diplomat's email, target Russian deputy minister
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hackers take over diplomat's email, target Russian deputy minister
-
APT37 Using a New Android Spyware, Chinotto
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT37 Using a New Android Spyware, Chinotto
-
ScarCruft surveilling North Korean defectors and human rights activists
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ScarCruft surveilling North Korean defectors and human rights activists
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
North Korean APT InkySquid Infects Victims Using Browser Exploits
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor North Korean APT InkySquid Infects Victims Using Browser Exploits
-
North Korean Cyberattacks A Dangerous and Evolving Threat 2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean Cyberattacks A Dangerous and Evolving Threat 2
-
volexity.com-North Korean BLUELIGHT Special InkySquid Deploys RokRAT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor volexity.com-North Korean BLUELIGHT Special InkySquid Deploys RokRAT
-
North Korean BLUELIGHT Special- InkySquid Deploys RokRAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean BLUELIGHT Special- InkySquid Deploys RokRAT
-
New variant of Konni malware used in campaign targetting Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New variant of Konni malware used in campaign targetting Russia
-
volexity.com-North Korean APT InkySquid Infects Victims Using Browser Exploits
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor volexity.com-North Korean APT InkySquid Infects Victims Using Browser Exploits
-
North Korean APT37 - InkySquid Infects Victims Using Browser Exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean APT37 - InkySquid Infects Victims Using Browser Exploits
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Retrohunting APT37- North Korean APT used VBA self decode technique to inject RokRat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Retrohunting APT37- North Korean APT used VBA self decode technique to inject RokRat
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor blog.malwarebytes.com-Retrohunting APT37 North Korean APT used VBA self decode technique to inject RokRat
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Greetings from Lazarus
-
Who is the Threat Actor Behind Operation Earth Kitsune-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is the Threat Actor Behind Operation Earth Kitsune-
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
APT_trends_report_Q3_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q3_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2020
-
The many personalities of Lazarus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The many personalities of Lazarus
-
Cloud Threat Landscape Report 2020,pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cloud Threat Landscape Report 2020,pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The 'Spy Cloud' Operation Geumseong121 group carries out the APT attack disguising the evidence of North Korean defection
-
Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Lexfo-WhitePaper-The_Lazarus_Constellation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lexfo-WhitePaper-The_Lazarus_Constellation
-
Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT Trends Report Q2 2018
-
The original link failed its last check. Original publisher Detailsfor mobile-malware-report.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor (cn)_higaisa_apt_report
-
APT_trends_report_Q2_2019_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2019_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2019
-
ScarCruft continues to evolve, introduces Bluetooth harvester
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ScarCruft continues to evolve, introduces Bluetooth harvester
-
ScarCruft continues to evolve, introduces Bluetooth harvester _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ScarCruft continues to evolve, introduces Bluetooth harvester _ Securelist
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2019.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-mtrends-2019
-
2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
-
2018 APT Summary Report CN version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 APT Summary Report CN version
-
Return to ROKRAT!! (feat. FAAAA...Sad...)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Return to ROKRAT!! (feat. FAAAA...Sad...)
-
APT37- Final1stspy Reaping the FreeMilk
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT37- Final1stspy Reaping the FreeMilk
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-apt38-2018-web_v4
-
APT37 Final1stspy Reaping the FreeMilk
The original link failed its last check. Detailsfor APT37 Final1stspy Reaping the FreeMilk
-
NOKKI Almost Ties the Knot with DOGCALL- Reaper Group Uses New Malware to Deploy RAT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NOKKI Almost Ties the Knot with DOGCALL- Reaper Group Uses New Malware to Deploy RAT
-
Report Ties North Korean Attacks to New Malware, Linked by Word Macros
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Report Ties North Korean Attacks to New Malware, Linked by Word Macros
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OPERATION "Rocket Man"
-
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families | McAfee Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families | McAfee Blogs
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Daybreak
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends Report Q2 2018
-
NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Red_Eyes_Hacking_Group_Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q1 2018
-
Reaper Group’s Updated Mobile Arsenal
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reaper Group’s Updated Mobile Arsenal
-
Fake AV Investigation Unearths KevDroid, New Android Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fake AV Investigation Unearths KevDroid, New Android Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco's Talos Intelligence Group Blog: NavRAT Uses US-North Korea Summit As Decoy For Attacks In South Korea
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tech_Report_Malicious_Hancom
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT37.blog
-
APT37 (Reaper)- The Overlooked North Korean Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT37 (Reaper)- The Overlooked North Korean Actor
-
The original link failed its last check. Original publisher Detailsfor rpt_APT37.pdf
-
APT37 (Reaper): The Overlooked North Korean Actor
The link to Mirror on Box failed its last check. Detailsfor APT37 (Reaper): The Overlooked North Korean Actor
-
APT37 (Reaper): The Overlooked North Korean Actor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT37 (Reaper): The Overlooked North Korean Actor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attacks Leveraging Adobe Zero-Day (CVE-2018-4878) – Threat Attribution, Attack Scenario and Recommendations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Korea In The Crosshairs
-
Cisco's Talos Intelligence Group Blog: Korea In The Crosshairs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco's Talos Intelligence Group Blog: Korea In The Crosshairs
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Talos_RokRatWhitePaper.pdf
-
Microsoft_Security_Intelligence_Report_Volume_21_English
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft_Security_Intelligence_Report_Volume_21_English
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Daybreak
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Daybreak
-
ScarCruft APT Group Used Latest Flash Zero Day in Two Dozen Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ScarCruft APT Group Used Latest Flash Zero Day in Two Dozen Attacks
-
Flash zero-day exploit deployed by the ScarCruft APT Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Flash zero-day exploit deployed by the ScarCruft APT Group
-
CVE-2016-4171 – Adobe Flash Zero-day used in targeted attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2016-4171 – Adobe Flash Zero-day used in targeted attacks
Newest first. Details opens the report in Explore.