#APT37
Hello, I wrote a new blog analyzing a sample from a recent APT37 phishing attack.

zw01f.github.io/malware%20an...

Would love to hear your feedback!
#RokRat #APT37 #ScarCruft #malware #APT #MalwareAnalysis #Infosec
APT37 - RokRat
An in-depth analysis of APT37’s latest campaign leveraging fileless RokRat malware
zw01f.github.io
March 9, 2025 at 10:09 PM
The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform.
ScarCruft hackers push BirdCall Android malware via game platform
The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform.
www.bleepingcomputer.com
May 5, 2026 at 9:04 AM
APT37 hackers use new malware to breach air-gapped networks
APT37 hackers use new malware to breach air-gapped networks
North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance.
www.bleepingcomputer.com
February 27, 2026 at 7:35 PM
This is very good malware.

This is solid-solid-SOLID B+ malware, very close to A- malware.

APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ...
April 13, 2026 at 5:13 PM
North Korean hackers from the KONNI activity cluster are abusing Google's Find Hub tool to track their targets' GPS positions and trigger remote factory resets of Android devices.
APT37 hackers abuse Google Find Hub in Android data-wiping attacks
North Korean hackers from the KONNI activity cluster are abusing Google's Find Hub tool to track their targets' GPS positions and trigger remote factory resets of Android devices.
www.bleepingcomputer.com
November 11, 2025 at 12:46 AM
North Korean APT37 is hiding malware in JPEG images! ⚠️ They're using a two-stage encrypted injection & .lnk shortcuts with Cmd/PowerShell to evade detection. #cybersecurity #threatintel #APT37

#crypto #blockchain #news
August 4, 2025 at 4:28 AM
How does North Korea-aligned ScarCruft (APT37) maintain long-term access across campaigns? #ESETresearch uncovered CinderRelay, a previously undocumented Linux server backdoor used to retain control of compromised infrastructure. 2/4
September 15, 2026 at 7:55 AM
-More PlugX sightings
-Storm-1516 campaigns shift from US to Ukraine's EU backers
-FAMOUS CHOLLIMA active with 26 npm packages
-APT37 adds air-gap malware
-Unfixed Matrix and Node.js bugs
-RCEs in Unitree robots
-3k Google API keys leaked online
-Log4j calls out AI sloppers
-Ton of new tools
March 2, 2026 at 9:17 AM
reserved for infected binaries, not self-delivered binaries.

Despite all of these super cool features, APT37 shoots themselves in the foot immediately.

- EAT walking for Kernel32 functionality (???)
- XOR decryption is a huge red flag
- Allocating with PAGE_EXECUTE_READWRITE (???)
-
April 13, 2026 at 5:13 PM
-Americans lost $388m to crypto ATMs
-FlowerStorm PhaaS adds VM-based obfuscation
-APT37 poses as the police
-Twill Typhoon's FDMTP backdoor
-New TencShell attacks
-Sandworm and Leek Likho activity still going
-UK sanctions Russian disinfo firms
-Malware reports on Gremlin Stealer, Vidar, XWorm
May 18, 2026 at 7:37 AM
APT37 hackers abuse Google Find Hub in Android data-wiping attacks #cybersecurity #infosec
APT37 hackers abuse Google Find Hub in Android data-wiping attacks
North Korean hackers from the KONNI activity cluster are abusing Google's Find Hub tool to track their targets' GPS positions and trigger remote factory resets of Android devices. [...]
www.bleepingcomputer.com
November 17, 2025 at 6:30 PM
North Korean hackers (APT37/ScarCruft) infiltrated Google Play with KoSpy spyware hidden in utility apps. KoSpy stole SMS and screenshots before Google removed the apps. The spyware, active since 2022, may be retired.#KoSpyThreat
March 12, 2025 at 4:19 PM
North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance.
APT37 hackers use new malware to breach air-gapped networks
North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance.
www.bleepingcomputer.com
February 27, 2026 at 7:21 PM
"Operation HanKook Phantom: APT37 Spear-Phishing Campaign" published by Seqrite. #APT37, #LNK, #RokRAT, #DPRK, #CTI https://www.seqrite.com/blog/operation-hankook-phantom-north-korean-apt37-targeting-south-korea/
August 29, 2025 at 1:30 PM
ScarCruft uses fake Microsoft security alerts in spear-phishing emails to deliver a ZIP with a malicious LNK, launching NarwhalRAT via multi-stage scripts and in-memory execution. #APT37 #NarwhalRAT #Korea
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
ScarCruft (APT37) is using spear-phishing emails that impersonate Microsoft Account security alerts to trick victims into opening a ZIP file that launches a malicious LNK and installs NarwhalRAT. The malware runs through a multi-stage, in-memory infection chain, collects sensitive data, and uses Korean websites plus pCloud as command-and-control channels. #ScarCruft #APT37...
www.hendryadrian.com
June 16, 2026 at 10:30 AM
APT37 Hackers Abusing Group Chats To Attack Via Malicious LNK File
APT37 Hackers Abusing Group Chats To Attack Via Malicious LNK File
cybersecuritynews.com
February 3, 2025 at 8:49 AM
March 12, 2025 at 1:30 PM
APT37 hackers use new malware to breach air-gapped networks
APT37 hackers use new malware to breach air-gapped networks
www.bleepingcomputer.com
February 27, 2026 at 8:06 PM
-BlackDB admin pleads guilty
-DDoS booters attempt comebacks in hours
-Ransomware gangs live around one year
-New Desolator and The Gentlemen RaaS
-New ZynorRAT, MostereRAT, RatOn, Salat Stealer, GPUGate malware
-New Salt Typhoon and APT37 infrastructure
-Patch Tuesday is out
-SessionReaper vuln
September 10, 2025 at 8:56 AM