Threat Actor ๐ฐ๐ต North Korea
APT37
Also known as: APT 37 ยท Group 123 ยท Group123 ยท InkySquid ยท Operation Daybreak ยท Operation Erebus ยท Reaper Group ยท Reaper ยท Red Eyes ยท Ricochet Chollima ยท ScarCruft ยท Venus 121 ยท ATK4 ยท G0067 ยท Moldy Pisces ยท APT-C-28
APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its targeting beyond the Korean peninsula to include Japan, Vietnam and the Middle East, and to a wider range of industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive and healthcare entities
Indicators of Compromise 12
Domain img[.]darklights[.]store Domain img[.]monderhouse[.]space Domain img[.]responsive[.]pstatic[.]autos Domain img[.]smartnords[.]site Domain img[.]socialteams[.]store Domain img[.]worksongo[.]store Filename /tmp/jasper-log Filename /var/lib/snapd/g580 Filename /var/lib/sshd/c8c68e629bba773a10ac80012d10bf19 Filename ~/cache/haproxy-1000.cache SHA-256 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5 SHA-256 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558