- May 4, 2019
- 825
At Zscaler ThreatLabz, we have been closely monitoring the tools, techniques and procedures (TTPs) of APT37 (also known as ScarCruft or Temp.Reaper) - a North Korea-based advanced persistent threat actor. This threat actor has been very active in February and March 2023 targeting individuals in various South Korean organizations.
During our threat hunting research, we came across a GitHub repository which is owned by a member of the threat actor group. Due to an operational security (OpSec) failure of the threat actor, we were able to access a wealth of information about the malicious files used by this APT group along with the timeline of their activities dating as far back as October 2020.
The Unintentional Leak: A glimpse into the attack vectors of APT37 | Zscaler
An operational security failure by the North Korean threat actor - APT37, led to the discovery of many previously unknown tools and techniques used by them
www.zscaler.com