Ricochet Chollima

Ricochet Chollima (also known as APT 37, Reaper, and ScarCruft) is a North Korean Advanced persistent threat group that is believed to be typically involved in operations against financial institutions to generate assets for North Korea. But also conducts attacks on industrial sector. Their attacks occur primarily on South Korea, but also in Japan, Vietnam and the Middle East.[1][2] FireEye has called the group "the overlooked North Korean actor."[3]

History

The group is believed to have been founded sometime around 2012, according to FireEye.[3]

In January 2021 the group was found to be using a Trojan horse for a spear-phishing campaign that targeted the South Korean government.[4][5]

See also

References

  1. Meyers, Adam (2018-04-06). "STARDUST CHOLLIMA | Threat Actor Profile | CrowdStrike". Retrieved 2021-03-15.
  2. Osborne, Charlie. "North Korean Reaper APT uses zero-day vulnerabilities to spy on governments". ZDNet. Retrieved 2021-03-15.
  3. "APT37 (Reaper) The Overlooked North Korean Actor" (PDF). FireEye.
  4. "ALERT: North Korean hackers targeting South Korea with RokRat Trojan". The Hacker News. Retrieved 2021-03-15.
  5. Team, Threat Intelligence (2021-01-06). "Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat". Malwarebytes Labs. Retrieved 2021-03-15.


This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.