APT37
APT37 is an advanced persistent threat (APT) group that has been active since at least 2014 and is believed to be based in North Korea. The group is known for its targeted attacks on organizations involved in the media, finance, and defense sectors, as well as governments around the world. APT37 uses a variety of tactics, including spear-phishing emails, malware drops, and social engineering techniques to gain access to their targets networks. Once inside, they can steal sensitive information or conduct destructive activities such as data deletion or network disruption. The group has been linked to several high-profile attacks, including the Sony Pictures Entertainment hack in 2014 and the WannaCry ransomware outbreak in May 2017.
Techniques, tactics and practices:
APT37 uses a variety of tactics to gain access to their targets networks, including spear-phishing emails that contain malicious attachments or links. Once inside, they may use social engineering techniques such as impersonating legitimate organizations in order to trick users into revealing sensitive information or downloading and installing malware on their devices. APT37 is also known for using customized malware tools designed specifically for each targeted organization, which can evade detection by traditional security measures. Additionally, the group has been linked to destructive activities such as data deletion or network disruption in order to cause harm and gain a strategic advantage over their targets.
