North KoreaWidely attributedUnknownMITRE G0067

APT37

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
2.4
Low signal strength
Mentions3
Sources1
High conf.3
Last seenMay 2026
First observed
2018-04-18
Last active
Origin
North Korea
Aliases
8
Techniques
29
Campaigns
0
North Korea

Attribution signals

3 mentions · 1 source
#1high
MalwareTTP matchVictimology
eset
May 2026
#2compromiseshigh
MalwareVictimology
wechat-qax-ti
May 2026

"APT group ScarCruft compromises gaming platform sqgame in China's Yanbian region"

#3likelyhigh
VictimologyGeopolitical
eset
May 2026

"ScarCruft compromised a gaming platform serving the Yanbian region in China, likely to collect intelligence on individuals of interest to the North Korean regime"

Hedge terms observed

compromiseslikely