APT37__2018__rpt_APT37.pdf
ID: 74b53f40-118a-4f05-91ad-965e93fd3901
STIX ID: report--74b53f40-118a-4f05-91ad-965e93fd3901
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2018-02-19
Last Modified Date: 2018-02-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report on APT37 (Reaper) describes a North Korean-aligned espionage actor active since at least 2012 that targets South Korea and regional actors, expanded to Japan, Vietnam and the Middle East, and uses spear phishing, strategic web compromises and torrent-distributed lures to deploy multiple malware families (DOGCALL, KARAE, SLOWDRIFT, RUHAPPY wiper, SHUTTERSPEED, etc.). The report documents exploitation of known and zero-day CVEs (notably CVE-2018-4878 and CVE-2017-0199), command-and-control via compromised sites and cloud APIs, technical indicators (hashes, CVEs), and behavioral evidence supporting attribution to North Korea.
