logo

APT37__2018__rpt_APT37.pdf

ID: 74b53f40-118a-4f05-91ad-965e93fd3901

STIX ID: report--74b53f40-118a-4f05-91ad-965e93fd3901

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2018-02-19

Last Modified Date: 2018-02-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report on APT37 (Reaper) describes a North Korean-aligned espionage actor active since at least 2012 that targets South Korea and regional actors, expanded to Japan, Vietnam and the Middle East, and uses spear phishing, strategic web compromises and torrent-distributed lures to deploy multiple malware families (DOGCALL, KARAE, SLOWDRIFT, RUHAPPY wiper, SHUTTERSPEED, etc.). The report documents exploitation of known and zero-day CVEs (notably CVE-2018-4878 and CVE-2017-0199), command-and-control via compromised sites and cloud APIs, technical indicators (hashes, CVEs), and behavioral evidence supporting attribution to North Korea.