APT37
MISPNation-state
KP
Unknown
[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. [APT37](https://attack.mitre.org/groups/G0067) has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123)
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
Tecniche Utilizzate (29)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1005 | Data from Local System | - |
| T1027 | Obfuscated Files or Information | - |
| T1027.003 | Steganography | - |
| T1033 | System Owner/User Discovery | - |
| T1036.001 | Invalid Code Signature | - |
| T1053.005 | Scheduled Task | - |
| T1055 | Process Injection | - |
| T1057 | Process Discovery | - |
| T1059 | Command and Scripting Interpreter | - |
| T1059.003 | Windows Command Shell | - |
| T1059.005 | Visual Basic | - |
| T1059.006 | Python | - |
| T1071.001 | Web Protocols | - |
| T1082 | System Information Discovery | - |
| T1102.002 | Bidirectional Communication | - |
Riferimenti (10)
- volexity.com - North Korean Apt Inkysquid Infects Victims Using Browser Exploits
- fireeye.com - Apt37 Overlooked North Korean Actor
- www2.fireeye.com - Rpt APT37.pdf
- blog.talosintelligence.com - Korea In Crosshairs
- twitter.com - 966126706107953152
- cfr.org - Apt 37
- bleepingcomputer.com - Report Ties North Korean Attacks To New Malware Linked By Word Macros
- unit42.paloaltonetworks.com - Unit42 Freemilk Highly Targeted Spear Phishing Campaign
- blog.talosintelligence.com - Korea In Crosshairs
- attack.mitre.org - G0067
Alias (4312)
Malware Utilizzato (13)
Metadata
| ID: | 160 |
| Created: | 13/01/2026 17:48 |
| Updated: | 21/04/2026 16:00 |