G0067

G0067APT37

Description

[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. [APT37](https://attack.mitre.org/groups/G0067) has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.

References

  1. https://attack.mitre.org/groups/G0067
  2. https://www.volexity.com/blog/2021/08/17/north-korean-apt-inkysquid-infects-victims-using-browser-exploits/
  3. https://www.crowdstrike.com/adversaries/ricochet-chollima/
  4. https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf
  5. https://securelist.com/scarcruft-continues-to-evolve-introduces-bluetooth-harvester/90729/
  6. https://blog.talosintelligence.com/2018/01/korea-in-crosshairs.html
  7. https://securelist.com/operation-daybreak/75100/

Software attributed to this8

TypeTargetConfidenceTier
SoftwareWINERACKs0219100%live
SoftwareSLOWDRIFTs0218100%live
SoftwareDOGCALLs0213100%live
SoftwareKONNIs0356100%live
SoftwareNOKKIs0353100%live
SoftwareKARAEs0215100%live
SoftwareBLUELIGHTs0657100%live
SoftwareCORALDECKs021295%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT38
Group
APT33
Actor
APT43
Group
APT19
Group
APT39
Actor
APT45
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.