⤷ Title: South Korean CSOs Under Cyberattack: 3-Year Study
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 14 Feb 2025 01:35:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT37 #Contagious Interview #Kimsuky #RambleOn Spyware #Reaper #RokRAT #SuperBear RAT #UCID902 #Velvet Chollima
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 14 Feb 2025 01:35:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT37 #Contagious Interview #Kimsuky #RambleOn Spyware #Reaper #RokRAT #SuperBear RAT #UCID902 #Velvet Chollima
Cybersecurity News
South Korean CSOs Under Cyberattack: 3-Year Study
Explore the impact of South Korean cyberattack threats on civil society organizations and their defenders in a detailed study.
⤷ Title: North Korean APT-C-28 Expands Cyber Espionage Campaign
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Mon, 24 Feb 2025 01:52:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT_C_28 #APT37 #Group123 #Reaper #RokRAT #ScarCruft
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Mon, 24 Feb 2025 01:52:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT_C_28 #APT37 #Group123 #Reaper #RokRAT #ScarCruft
Daily CyberSecurity
North Korean APT-C-28 Expands Cyber Espionage Campaign
Learn how APT-C-28 operates in cyber espionage, targeting industries with advanced techniques and the RokRat Trojan.
⤷ Title: Squid Werewolf APT Masquerades as Recruiters in Espionage Campaign Targeting Key Employees
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Sat, 15 Mar 2025 01:38:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT37 #Reaper Group #Ricochet Chollima #ScarCruft #Squid Werewolf
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Sat, 15 Mar 2025 01:38:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT37 #Reaper Group #Ricochet Chollima #ScarCruft #Squid Werewolf
Daily CyberSecurity
Squid Werewolf APT Masquerades as Recruiters in Espionage Campaign Targeting Key Employees
Uncover the Squid Werewolf cyber-espionage campaign and its tactics to exploit fake job offers for cyberattacks.
⤷ Title: North Korean ScarCruft APT Targets Users with Novel KoSpy Android Spyware
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Sun, 16 Mar 2025 01:52:14 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #KoSpy Android Spyware #ScarCruft
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Sun, 16 Mar 2025 01:52:14 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #KoSpy Android Spyware #ScarCruft
Daily CyberSecurity
North Korean ScarCruft APT Targets Users with Novel KoSpy Android Spyware
Uncover insights on KoSpy Android Spyware, a new threat targeting Korean and English-speaking users with deceptive utility apps.
⤷ Title: Konni RAT Resurfaces: North Korean Espionage Malware Evolves with Stealth and Persistence
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 00:16:10 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Konni RAT #powershell
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 00:16:10 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Konni RAT #powershell
Daily CyberSecurity
Konni RAT Resurfaces: North Korean Espionage Malware Evolves with Stealth and Persistence
Explore the dangers of Konni RAT, a sophisticated Remote Access Trojan targeting Windows systems with multi-stage attacks.
⤷ Title: North Korean APT37’s “ToyBox Story”: Stealthy Attacks Unveiled
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 May 2025 00:40:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT37 #cloud #cyberattack #dropbox #Fileless Malware #malware #North Korea #RokRAT #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 May 2025 00:40:49 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT37 #cloud #cyberattack #dropbox #Fileless Malware #malware #North Korea #RokRAT #spear_phishing
Daily CyberSecurity
North Korean APT37's "ToyBox Story": Stealthy Attacks Unveiled
New report details APT37's "ToyBox Story" campaign, using spear phishing and cloud services to deploy RoKRAT malware. Fileless attacks and stealthy tactics revealed.
⤷ Title: APT37’s Stealthy RoKRAT Malware Uses Steganography in JPEGs to Evade Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 03:11:55 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Cyberespionage #cybersecurity #DLL hijacking #Fileless Malware #malware #North Korea #RoKRAT #Steganography
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 Aug 2025 03:11:55 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Cyberespionage #cybersecurity #DLL hijacking #Fileless Malware #malware #North Korea #RoKRAT #Steganography
Penetration Testing Tools
APT37's Stealthy RoKRAT Malware Uses Steganography in JPEGs to Evade Detection
APT37's new RoKRAT malware variant uses steganography to hide encrypted payloads in JPEG images, bypassing antivirus and traditional defenses by executing entirely in memory.
⤷ Title: ScarCruft APT Deploys VCD Ransomware, Uses PubNub & New Malware in Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #APT37 #Cyberespionage #malware #North Korea #NubSpy #PubNub #ScarCruft #VCD Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 00:11:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #APT37 #Cyberespionage #malware #North Korea #NubSpy #PubNub #ScarCruft #VCD Ransomware
Daily CyberSecurity
ScarCruft APT Deploys VCD Ransomware, Uses PubNub & New Malware in Espionage Campaign
S2W’s Threat Analysis and Intelligence Center (TALON) has uncovered a sophisticated malware campaign attributed to the North Korean APT group ScarCruft (a.k.a. APT37, Reaper, Ricochet Chollima). T…
⤷ Title: From Lure to Shell: Reproducing APT37’s CHM Exploitation Tactics
════════════════════════
𐀪 Author: Alok kumar
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 19:14:53 GMT
════════════════════════
⌗ Tags: #mitre_attack #red_team #apt37 #social_engineering #infosec
════════════════════════
𐀪 Author: Alok kumar
════════════════════════
ⴵ Time: Fri, 22 Aug 2025 19:14:53 GMT
════════════════════════
⌗ Tags: #mitre_attack #red_team #apt37 #social_engineering #infosec
Medium
From Lure to Shell: Reproducing APT37’s CHM Exploitation Tactics
Reproducing the tactics of APT37, this blog shows how CHM files can be weaponized for threat emulation. From lure design to reverse shell.
⤷ Title: North Korea’s ScarCruft Targets Academics With RokRAT Malware
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 17:21:51 +0000
════════════════════════
⌗ Tags: #Security #Malware #APT37 #Cyber Attack #Cybersecurity #HanKook Phantom #North Korea #Phishing #RokRAT #ScarCruft
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 01 Sep 2025 17:21:51 +0000
════════════════════════
⌗ Tags: #Security #Malware #APT37 #Cyber Attack #Cybersecurity #HanKook Phantom #North Korea #Phishing #RokRAT #ScarCruft
Hackread
North Korea’s ScarCruft Targets Academics With RokRAT Malware
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: North Korean Hackers Launch Widespread Cyberespionage Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 04:14:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT37 #Cyberespionage #cybersecurity #LNK file #North Korea #RoKRAT #ScarCruft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Sep 2025 04:14:36 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT37 #Cyberespionage #cybersecurity #LNK file #North Korea #RoKRAT #ScarCruft
Penetration Testing Tools
North Korean Hackers Launch Widespread Cyberespionage Campaign
A North Korean hacking group, APT37, is targeting government and research organizations with a new cyberespionage campaign using a malicious LNK file.
⤷ Title: APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:01:29 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Chinotto #cyber_espionage #cybersecurity #malware #North Korea #Rustonotto #ScarCruft #Zscaler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 10 Sep 2025 00:01:29 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Chinotto #cyber_espionage #cybersecurity #malware #North Korea #Rustonotto #ScarCruft #Zscaler
Daily CyberSecurity
APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer
A new report reveals North Korea's APT37 is using Rust-based malware called Rustonotto, marking a shift toward modern languages and multi-platform attacks.
⤷ Title: Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 14:19:34 +0000
════════════════════════
⌗ Tags: #Android #Malware #Scams and Fraud #Security #APT37 #Cyber Attack #Cybersecurity #Google Fund Hub #KakaoTalk #Kimsuky #Konni #North Korea #South Korea
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 12 Nov 2025 14:19:34 +0000
════════════════════════
⌗ Tags: #Android #Malware #Scams and Fraud #Security #APT37 #Cyber Attack #Cybersecurity #Google Fund Hub #KakaoTalk #Kimsuky #Konni #North Korea #South Korea
Hackread
Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack
North Korea-linked KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe Android devices in a targeted phishing campaign.
⤷ Title: “Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT37 #Artemis Campaign #cyber_espionage #Genians Security Center #HWP Malware #North Korea #pCloud #Reaper #Ricochet Chollima #social engineering #Yandex Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 00:35:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT37 #Artemis Campaign #cyber_espionage #Genians Security Center #HWP Malware #North Korea #pCloud #Reaper #Ricochet Chollima #social engineering #Yandex Cloud
Daily CyberSecurity
“Casting Call” for Malware: APT37 Poses as TV Writers to Hack Targets
A notorious threat group is auditioning victims for a new cyber-espionage campaign, masquerading as television production staff to slip malware past defenses. A new report from Genians Security Ce…
⤷ Title: Operation Artemis: North Korean ScarCruft Hijacks HWP Files to Deploy RoKRAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 03:00:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT37 #Cyber Espionage #DLL side_loading #Genians #HWP #Operation Artemis #phishing #RoKRAT #ScarCruft #South Korea #Steganography
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 03:00:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT37 #Cyber Espionage #DLL side_loading #Genians #HWP #Operation Artemis #phishing #RoKRAT #ScarCruft #South Korea #Steganography
Penetration Testing Tools
Operation Artemis: North Korean ScarCruft Hijacks HWP Files to Deploy RoKRAT
As part of a large-scale malware campaign dubbed Operation Artemis, the North Korean hacking group APT37—also known as
⤷ Title: Atomic Red Team notes — TryHackMe
════════════════════════
𐀪 Author: Jose Praveen
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 12:22:39 GMT
════════════════════════
⌗ Tags: #apt37 #powershell #atomic_red_team #tryhackme
════════════════════════
𐀪 Author: Jose Praveen
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 12:22:39 GMT
════════════════════════
⌗ Tags: #apt37 #powershell #atomic_red_team #tryhackme
Medium
Atomic Red Team notes — TryHackMe
Leveraging the Atomic Red Team Framework to strengthen the Security Operations’ detection capabilities.
⤷ Title: Bridging the Gap: North Korean APT37 Deploys ‘Ruby Jumper’ to Infiltrate Isolated Air-Gapped Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 00:05:18 +0000
════════════════════════
⌗ Tags: #Malware #Air_gap attack #APT37 #Cloud C2 #infosec #North Korean APT #Ruby Jumper #ScarCruft #SNAKEDROPPER #THUMBSBD #USB malware #VIRUSTASK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 00:05:18 +0000
════════════════════════
⌗ Tags: #Malware #Air_gap attack #APT37 #Cloud C2 #infosec #North Korean APT #Ruby Jumper #ScarCruft #SNAKEDROPPER #THUMBSBD #USB malware #VIRUSTASK
Daily CyberSecurity
Bridging the Gap: North Korean APT37 Deploys 'Ruby Jumper' to Infiltrate Isolated Air-Gapped Networks
Zscaler unmasked APT37's "Ruby Jumper" campaign, which uses weaponized USBs and cloud services to bypass network isolation and steal data from air-gapped systems.
⤷ Title: Jumping the Gap: APT37’s “Ruby Jumper” Campaign Weaponizes Cloud Storage and USBs to Breach Isolated Networks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 07:01:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #air_gapped network #APT37 #Cybersecurity 2026 #RESTLEAF #Ruby Jumper #ScarCruft #SNAKEDROPPER #THUMBSBD #USB Malware #Velvet Chollima #VIRUSTASK #Zoho WorkDrive #Zscaler ThreatLabz
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 07:01:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #air_gapped network #APT37 #Cybersecurity 2026 #RESTLEAF #Ruby Jumper #ScarCruft #SNAKEDROPPER #THUMBSBD #USB Malware #Velvet Chollima #VIRUSTASK #Zoho WorkDrive #Zscaler ThreatLabz
Penetration Testing Tools
Jumping the Gap: APT37’s "Ruby Jumper" Campaign Weaponizes Cloud Storage and USBs to Breach Isolated Networks
The DPRK-affiliated syndicate APT37 has augmented its arsenal dedicated to breaching air-gapped networks. The Zscaler ThreatLabz vanguard has
⤷ Title: The Friend Request from Pyongyang: How APT37 Hijacks Facebook to Deploy RokRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:40:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT37 #Code Cave Injection #Facebook Phishing #Fileless Malware #Genians Security Center #North Korean APT #PE Patching #RokRAT #social engineering #Wondershare PDFelement #Zoho WorkDrive
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 07:40:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT37 #Code Cave Injection #Facebook Phishing #Fileless Malware #Genians Security Center #North Korean APT #PE Patching #RokRAT #social engineering #Wondershare PDFelement #Zoho WorkDrive
Daily CyberSecurity
The Friend Request from Pyongyang: How APT37 Hijacks Facebook to Deploy RokRAT
APT37 pivots to Facebook social engineering, using Wondershare PDFelement "code caves" to deploy RokRAT. Learn how they bypass EDR with memory-only payloads.