Adversary-emulation profile for APT37 (G0067 / Reaper / ScarCruft / Ricochet Chollima / InkySquid / Group123), North Korea's RGB cyber-espionage actor.
59
68%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt37-reaper/SKILL.mdAPT37 (MITRE ATT&CK G0067) is a North Korean state-sponsored cyber-espionage group active since at least 2012. Tracked as ScarCruft (Kaspersky), Reaper (FireEye), InkySquid (Volexity), Group123 (Cisco Talos), TEMP.Reaper, and Ricochet Chollima (CrowdStrike), APT37 primarily targets South Korean government, military, media, and defector communities, with expanding operations into Japan, Vietnam, the Middle East, and Europe. The group is characterized by aggressive exploitation of zero-day vulnerabilities in Adobe Flash Player, Internet Explorer, and Microsoft Edge; heavy use of weaponized Hangul Word Processor (HWP) documents; strategic web compromises (watering holes); a diverse custom malware arsenal (RoKRAT, BLUELIGHT, Chinotto, Dolphin, DOGCALL); and C2 over legitimate cloud services (Dropbox, pCloud, Yandex, Box, Google Drive). Unlike the higher-profile Lazarus Group, APT37 focuses on targeted intelligence collection and defector surveillance rather than financial theft or destructive operations.
HKCU\Software\Microsoft\CurrentVersion\Run\ registry keys.cmd.exe using VirtualAlloc/WriteProcessMemory/CreateRemoteThread for execution in a legitimate process context.shutdown /r /t 1 to reboot systems after MBR wipe.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| ROKRAT | S0240 | Modular RAT; cloud-service C2 (Dropbox/pCloud/Yandex/Box); screen/audio/keylog/clipboard | Custom |
| BLUELIGHT | S0657 | Multi-function backdoor; Microsoft Graph API (OneDrive/Outlook) for C2 | Custom |
| DOGCALL | S0213 | Backdoor with audio/keylog/screen capture; cloud C2 | Custom |
| CORALDECK | S0212 | Exfiltration tool; archives and uploads files | Custom |
| HAPPYWORK | S0214 | Downloader for second-stage payloads | Custom |
| KARAE | S0215 | Backdoor distributed via torrent sites; cloud C2 | Custom |
| POORAIM | S0216 | Backdoor with screen capture; AOL IM C2 | Custom |
| SHUTTERSPEED | S0217 | Screenshot capture utility | Custom |
| SLOWDRIFT | S0218 | Cloud-based backdoor/downloader | Custom |
| WINERACK | S0219 | Backdoor with reverse shell; process/file enumeration | Custom |
| NavRAT | S0247 | RAT using Naver email for C2; keylogging | Custom |
| Final1stspy | S0355 | Reconnaissance downloader | Custom |
| KONNI | S0356 | RAT delivered via phishing; batch/PS/VBS multi-stage; credential theft | Custom (possibly shared) |
| Chinotto | (no ATT&CK software ID) | Multi-platform (Windows + Android) surveillance implant | Custom |
| GOLDBACKDOOR | (no ATT&CK software ID) | Backdoor delivered via LNK lures; targeted journalists | Custom |
| M2RAT | (no ATT&CK software ID) | RAT with AV evasion; Windows/mobile data theft | Custom |
| FadeStealer | (no ATT&CK software ID) | Surveillance tool: keylog, screenshot, audio, device monitor; RAR exfil | Custom |
| Dolphin | (no ATT&CK software ID) | Backdoor with Google Drive C2; broad collection capability | Custom |
| KoSpy | (no ATT&CK software ID) | Android spyware; SMS/call/location/audio/screenshot collection | Custom |
| SOUNDWAVE | (no ATT&CK software ID) | Audio capture utility (microphone recording) | Custom |
| RICECURRY | (no ATT&CK software ID) | JavaScript browser profiler for watering-hole victim filtering | Custom |
| ZUMKONG | (no ATT&CK software ID) | Browser credential stealer | Custom |
| Cobalt Strike | S0154 | Post-exploitation framework (deployed via InkySquid browser exploits) | Public |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never run destructive (T1561/T1529 MBR wipe) actions outside an explicitly sanctioned, isolated lab.
Map APT37's signature plays to Decepticon's own capabilities:
.hwp-themed lures or macro-laden .doc files relevant to defector/journalist/government themes. Stage delivery with spearphishing pretexts tied to North Korea news, human-rights reports, or ROK government topics.cmd.exe.HKCU\...\Run); create scheduled tasks for script-based persistence; implement UAC bypass in the dropper chain; inject into legitimate processes (RoKRAT → cmd.exe pattern).shutdown /r /t 1). This demonstrates APT37's destructive potential without operational risk.<script> tags on high-value Korean-language sites.cmd.exe spawning with suspicious parent processes (HWP, Word); deploy endpoint-level API monitoring.HKCU\Software\Microsoft\CurrentVersion\Run and startup folder modifications; alert on registry changes from script interpreters or unsigned binaries.\\.\PhysicalDrive0; alert on shutdown /r /t 1 from non-administrative contexts; deploy MBR integrity monitoring.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.