FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAPT37 | APT37 has collected data from victims' local systems. |
| T1007 System Service Discovery |
MalwareWINERACK | WINERACK can enumerate services. |
| T1010 Application Window Discovery |
MalwareWINERACK | WINERACK can enumerate active windows. |
| T1033 System Owner/User Discovery |
MalwareWINERACK | WINERACK can gather information on the victim username. |
| T1033 System Owner/User Discovery |
MalwareHAPPYWORK | can collect the victim user name. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareCORALDECK | CORALDECK has exfiltrated data in HTTP POST headers. |
| T1056.001 Keylogging |
MalwareDOGCALL | DOGCALL is capable of logging keystrokes. |
| T1057 Process Discovery |
MalwarePOORAIM | POORAIM can enumerate processes. |
| T1057 Process Discovery |
MalwareWINERACK | WINERACK can enumerate processes. |
| T1059 Command and Scripting Interpreter |
MalwareWINERACK | WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands. |
| T1059.003 Windows Command Shell |
GroupAPT37 | APT37 has used the command-line interface. |
| T1082 System Information Discovery |
MalwareWINERACK | WINERACK can gather information about the host. |
| T1082 System Information Discovery |
MalwarePOORAIM | POORAIM can identify system information, including battery status. |
| T1082 System Information Discovery |
MalwareSLOWDRIFT | SLOWDRIFT collects and sends system information to its C2. |
| T1082 System Information Discovery |
MalwareKARAE | KARAE can collect system information. |
| T1082 System Information Discovery |
MalwareSHUTTERSPEED | SHUTTERSPEED can collect system information. |
| T1082 System Information Discovery |
MalwareHAPPYWORK | can collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path. |
| T1083 File and Directory Discovery |
MalwareCORALDECK | CORALDECK searches for specified files. |
| T1083 File and Directory Discovery |
MalwareWINERACK | WINERACK can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwarePOORAIM | POORAIM can conduct file browsing. |
| T1102.002 Bidirectional Communication |
MalwareSLOWDRIFT | SLOWDRIFT uses cloud based services for C2. |
| T1102.002 Bidirectional Communication |
MalwareKARAE | KARAE can use public cloud-based storage providers for command and control. |
| T1102.002 Bidirectional Communication |
GroupAPT37 | APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2. |
| T1102.002 Bidirectional Communication |
MalwarePOORAIM | POORAIM has used AOL Instant Messenger for C2. |
| T1102.002 Bidirectional Communication |
MalwareDOGCALL | DOGCALL is capable of leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex for C2. |
| T1105 Ingress Tool Transfer |
MalwareSHUTTERSPEED | SHUTTERSPEED can download and execute an arbitary executable. |
| T1105 Ingress Tool Transfer |
MalwareSLOWDRIFT | SLOWDRIFT downloads additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareKARAE | KARAE can upload and download files, including second-stage malware. |
| T1105 Ingress Tool Transfer |
GroupAPT37 | APT37 has downloaded second stage malware from compromised websites. |
| T1105 Ingress Tool Transfer |
MalwareHAPPYWORK | can download and execute a second-stage payload. |
| T1113 Screen Capture |
MalwareSHUTTERSPEED | SHUTTERSPEED can capture screenshots. |
| T1113 Screen Capture |
MalwareDOGCALL | DOGCALL is capable of capturing screenshots of the victim's machine. |
| T1113 Screen Capture |
MalwarePOORAIM | POORAIM can perform screen capturing. |
| T1123 Audio Capture |
GroupAPT37 | APT37 has used an audio capturing utility known as SOUNDWAVE that captures microphone input. |
| T1189 Drive-by Compromise |
MalwareKARAE | KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure. |
| T1189 Drive-by Compromise |
GroupAPT37 | APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly. |
| T1189 Drive-by Compromise |
MalwarePOORAIM | POORAIM has been delivered through compromised sites acting as watering holes. |
| T1203 Exploitation for Client Execution |
GroupAPT37 | APT37 has used exploits for Flash Player (CVE-2016-4117, CVE-2018-4878), Word (CVE-2017-0199), Internet Explorer (CVE-2020-1380 and CVE-2020-26411), and Microsoft Edge (CVE-2021-26411) for execution. |
| T1204.002 Malicious File |
GroupAPT37 | APT37 has sent spearphishing attachments attempting to get a user to open them. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT37 | APT37's has added persistence via the Registry key |
| T1555.003 Credentials from Web Browsers |
GroupAPT37 | APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers. |
| T1560.001 Archive via Utility |
MalwareCORALDECK | CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated. |
| T1561.002 Disk Structure Wipe |
GroupAPT37 | APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). |
| T1566.001 Spearphishing Attachment |
GroupAPT37 | APT37 delivers malware using spearphishing emails with malicious HWP attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.