APT37 (as known as Reaper) threat actor
APT37 is a North Korean state-sponsored cyber espionage group active since at least 2012. It is best known for stealthy, long-running intelligence collection against South Korean targets, and it has steadily widened its reach and sharpened its tradecraft over the past decade. The group is tracked under many names, most commonly Reaper and ScarCruft, and MITRE ATT&CK catalogs it as G0067. Its signature tool, a remote access trojan called ROKRAT, and its habit of hiding command-and-control traffic inside ordinary cloud services have become defining traits. Compared with North Korea's financially motivated operations, APT37 is an intelligence unit first. Its job is to gather information that supports the regime's political, military, and economic decisions, and its targeting reflects that: the people and institutions that shape or study policy toward North Korea. This page covers the group's attribution and aliases, who it targets, how it operates, its notable campaigns, and how organizations defend against an actor built for quiet, persistent access.
Key takeaways
- APT37 is a North Korean state-sponsored espionage group, active since at least 2012 and focused on intelligence collection rather than financial gain.
- It has many names. Reaper, ScarCruft, Group123, InkySquid, TEMP.Reaper, and Ricochet Chollima all refer to the same actor, tracked by MITRE as G0067.
- South Korea is the primary target, especially government, defense, media, academics, defectors, and experts on North Korean affairs, with activity also seen elsewhere in Asia and beyond.
- ROKRAT and cloud C2 are its signature. The group leans on the ROKRAT trojan and hides command-and-control traffic inside legitimate services such as Dropbox, pCloud, and Yandex.
- It uses zero-days and spearphishing. APT37 has repeatedly chained zero-day exploits with tailored spearphishing, and continues to run active campaigns into 2025.
Attribution and aliases
APT37 is widely attributed to North Korea, and several vendors link it specifically to the country's Ministry of State Security, which sets it apart from the finance-focused clusters usually grouped under the Lazarus Group umbrella. Attribution rests on consistent targeting aligned with North Korean intelligence priorities, shared malware and infrastructure across campaigns, and operational patterns documented over more than a decade by firms including Mandiant, Kaspersky, Volexity, and Cisco Talos.
Because so many teams have tracked the group independently, it carries a long list of names.
Common designations are:
- APT37
- Reaper
- ScarCruft
- Group123
- InkySquid
- Ricochet Chollima
- TEMP.Reaper
They all point to the same actor. One caveat is worth stating: North Korean group boundaries overlap, and some researchers report all state-sponsored activity from the country under Lazarus rather than separating out clusters like APT37, so occasional attribution differences between vendors are normal.
Who APT37 targets
APT37's targeting maps directly onto North Korean intelligence interests. South Korea has always been the center of gravity, and within it the group concentrates on government institutions, the military and defense industry, media outlets, financial organizations, and politically active individuals connected to North Korean topics. It has a particular focus on people who study or influence the regime: North Korea experts, academics, think-tank researchers, journalists covering the country, defectors, and human-rights activists.
The group's reach extends beyond the peninsula. Reporting has placed its activity in Japan, Vietnam, Russia, China, Nepal, India, the Middle East, and parts of Europe and the United States, usually where a target holds information relevant to Pyongyang. The goal is consistent throughout: gather strategic intelligence that can feed North Korea's decision-making rather than steal money or cause disruption for its own sake.
How APT37 operates
APT37's tradecraft favors stealth and patience, and it has evolved considerably while keeping a recognizable core. Its activity maps cleanly onto the MITRE ATT&CK framework.
On the malware side, the group's best-known tool is ROKRAT, a remote access trojan that uses cloud services for command-and-control and can capture screenshots, harvest credentials, and run further payloads. Its wider toolset has included DOGCALL, BLUELIGHT, CORALDECK, the Dolphin backdoor, and M2RAT, and in 2025 researchers documented KoSpy, an Android surveillance tool, showing the group extending onto mobile. APT37 also uses off-the-shelf tooling such as Cobalt Strike when it suits an operation. A recurring theme is the use of legitimate cloud platforms for C2, which is what makes its traffic hard to separate from everyday activity.
The group has evolved noticeably over the years. Early operations leaned on document exploits and custom backdoors; more recent ones favor fileless execution, LNK-based loaders, and abuse of cloud authorization, and its move onto Android shows it following targets across devices. One point worth noting is that although APT37 is an espionage actor at heart, it has held destructive capability, including malware able to overwrite a system's Master Boot Record, so its intent in a given intrusion should not be assumed to be collection alone.
Notable campaigns
APT37's history is a long series of espionage operations, many named by the researchers who exposed them:
- Operation Daybreak (2016) used a Flash Player zero-day in a watering-hole campaign, with a profiler called RICECURRY filtering visitors so only relevant targets received the exploit.
- Operation FreeMilk (2017) showed reach beyond Korea, compromising a financial institution's email to spearphish a second bank using an Office vulnerability.
- The InkySquid campaigns (2021), documented by Volexity, compromised a South Korean news site to deliver malware through browser exploits.
- Dolphin (2022) was a more capable backdoor used against South Korean targets, able to search drives and monitor connected devices.
- 2024 and 2025 activity continued at pace, including exploitation of a Windows vulnerability (CVE-2024-38178) to deploy ROKRAT, campaigns against North Korea experts and academics using Dropbox-based delivery, and the KoSpy Android spyware, confirming the group remains highly active.
How to defend against APT37
Because APT37 relies on tailored social engineering and legitimate services rather than noisy intrusions, defense centers on email security, patching, and behavioral detection:
- Harden against spearphishing. Advanced email filtering, attachment analysis, and user awareness reduce the group's main entry point, which is a convincing lure with a malicious document or link.
- Patch quickly. Since APT37 chains zero-day and known exploits in browsers, Office, and Windows, prompt patching closes the vulnerabilities its access depends on.
- Watch cloud services for abuse. Because command-and-control hides in Dropbox, pCloud, and similar platforms, monitoring for anomalous use of legitimate cloud services is more effective than blocklists alone.
- Hunt for living-off-the-land activity. Monitor PowerShell, scheduled tasks, and DLL sideloading, and correlate those signals across endpoint and network to surface stealthy, low-volume intrusions.
- Use threat intelligence. Tracking APT37's known tooling, infrastructure, and current campaigns helps teams recognize its activity in context and prioritize the sectors it targets.
Expert insight: tradecraft that hides in the ordinary
What makes APT37 hard to catch is not exotic technology, it is discipline. The group delivers a believable document to exactly the right person, executes in memory with tools already present on the system, and then talks to its operators through the same cloud services the target uses every day. Each step is designed to look normal. A signature-based control sees a Dropbox connection and a PowerShell process, both of which are unremarkable on their own, and the intrusion proceeds quietly.
This is where a CTI-led approach earns its place. Sekoia is a European cybersecurity vendor whose in-house Threat Detection & Research (TDR) team tracks nation-state actors such as APT37, and that intelligence feeds the platform so that the group's known tooling, infrastructure, and technique patterns are recognized in context. Rather than treating a single cloud connection or script as isolated noise, Sekoia's AI SOC platform correlates signals across endpoint, network, and cloud and maps them to MITRE ATT&CK, so that a spearphishing document leading to fileless execution and cloud-based command-and-control can be seen as one chain of activity rather than a set of unrelated events.
The practical point for defenders is that an actor this careful is caught through context, not through any one alert. Prevention such as patching and email filtering is essential and will stop a share of attempts, but the intrusions that get through are the ones that look ordinary, and those surface only when identity, endpoint, network, and cloud telemetry are read together against current intelligence. As a European vendor with a data-sovereignty posture, Sekoia is built for that kind of cross-surface visibility.