APT37
APT37 (Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group 123 / TEMP.Reaper / RedEyes / Geumseong121 / Venus 121 / Moldy Pisces / APT-C-28 / ATK4 / G0067) is a North Korean state-sponsored cyber-espionage actor active since at least 2012, attributed to the DPRK Reconnaissance General Bureau and operationally distinct from Lazarus, APT38/Bluenoroff, and Kimsuky.
the most-aliased DPRK cluster in public reporting (~12 tracked names) with a mission focus on geopolitical intelligence collection, distinct from APT38's financial-heist mandate and Kimsuky's policy-research surveillance, targeting South Korean government, ministry of unification, think tanks, North Korean defectors, journalists, and human-rights organizations, expanding since 2017 to Japan, Vietnam, the Middle East, and recently Czechia and Poland.
APT37 is technically distinguished by sustained zero-day capability across browser and Flash exploitation over more than a decade (CVE-2016-4171 Operation Daybreak, CVE-2016-7892 Operation Erebus, CVE-2018-4878, CVE-2020-1380, CVE-2021-26411 InkySquid, CVE-2022-41128 Itaewon- themed Google TAG disclosure), uncommonly resourced among DPRK clusters.
tradecraft signatures include the long-running RokRAT implant family, heavy legitimate-cloud-service abuse for C2 (Dropbox, Google Drive, Yandex, pCloud, GitHub), watering-hole compromises of South Korean-focused websites, Android surveillance implants (KevDroid), Bluetooth-device proximity-fingerprinting, sophisticated multi-stage Python implants (Dolphin, ESET 2022), and recent cloud OAuth refresh-token abuse for stealthy re-entry.