Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0067
MITRE ATT&CK Group

APT37 (G0067)

InkySquidScarCruftReaperGroup123TEMP.ReaperRicochet Chollima
ShareXLinkedInRedditHN

[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. [APT37](https://attack.mitre.org/groups/G0067) has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.(Citation: FireEye APT37 Feb 2018)(Citation: Securelist ScarCruft Jun 2016)(Citation: Talos Group123) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.

▪Techniques used (29)

T1547.001Registry Run Keys / Startup FolderT1120Peripheral Device DiscoveryT1059.006PythonT1105Ingress Tool TransferT1071.001Web ProtocolsT1027.003SteganographyT1102.002Bidirectional CommunicationT1082System Information DiscoveryT1204.002Malicious FileT1036.001Invalid Code SignatureT1548.002Bypass User Account ControlT1033System Owner/User DiscoveryT1555.003Credentials from Web BrowsersT1529System Shutdown/RebootT1005Data from Local SystemT1559.002Dynamic Data ExchangeT1106Native APIT1203Exploitation for Client ExecutionT1055Process InjectionT1027Obfuscated Files or InformationT1189Drive-by CompromiseT1057Process DiscoveryT1059Command and Scripting InterpreterT1059.003Windows Command ShellT1566.001Spearphishing AttachmentT1123Audio CaptureT1059.005Visual BasicT1053.005Scheduled TaskT1561.002Disk Structure Wipe

▪Software used (13)

S0657BLUELIGHTmalwareS0212CORALDECKmalwareS0215KARAEmalwareS0218SLOWDRIFTmalwareS0240ROKRATmalwareS0217SHUTTERSPEEDmalwareS0216POORAIMmalwareS0214HAPPYWORKmalwareS0355Final1stspymalwareS0154Cobalt StrikemalwareS0247NavRATmalwareS0213DOGCALLmalwareS0219WINERACKmalware
G0067on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.