{
  "family": "scarcruft",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nScarCruft (also known widely as APT37, Reaper, or Group123) is a highly capable, state-sponsored Advanced Persistent Threat (APT) group believed to operate out of North Korea. Active since at least 2012, ScarCruft is primarily focused on cyber-espionage and intelligence gathering, specifically targeting South Korean government entities, defectors, journalists, and defense contractors across East Asia and the Middle East.\n\n<h3>Technical Capabilities and Attack Lifecycle</h3>\nScarCruft is known for its agility and rapid adoption of newly disclosed zero-day vulnerabilities (particularly in Adobe Flash and Microsoft Office) to facilitate initial access.\n\nThe group's operational lifecycle is heavily focused on stealth and data extraction:\n<ul>\n<li><strong>Targeted Spear-Phishing:</strong> Campaigns begin with meticulously crafted emails containing weaponized documents relevant to the target's geopolitical interests (e.g., inter-Korean relations). These documents exploit vulnerabilities to silently drop the initial payload.</li>\n<li><strong>Custom Tooling (ROKrat/DogCall):</strong> ScarCruft heavily relies on a custom, sophisticated Remote Access Trojan (RAT) known as ROKrat (or DogCall). This malware is engineered for deep persistence and extensive intelligence gathering, including keystroke logging, audio recording via the microphone, and stealthy screen captures.</li>\n<li><strong>Covert Exfiltration:</strong> To bypass network perimeter defenses, ScarCruft frequently utilizes legitimate cloud services (like Yandex, Dropbox, or pCloud) as their command-and-control (C2) infrastructure. Stolen data is encrypted and silently uploaded to these trusted domains, making the exfiltration traffic incredibly difficult to distinguish from normal user activity.</li>\n</ul>\n\n<h3>Threat Impact</h3>\nA ScarCruft compromise is a severe national security incident. The group's primary objective is the theft of classified political, military, and strategic intelligence, which directly supports the objectives of the North Korean state apparatus.\n\n<h3>Defense and Resilience Strategies</h3>\n<ul>\n<li><strong>Rapid Patch Management:</strong> Because ScarCruft is known to rapidly weaponize zero-day and N-day vulnerabilities, organizations must maintain an aggressive patching cadence for all operating systems and third-party applications (especially Office and browsers).</li>\n<li><strong>Behavioral Analytics and EDR:</strong> Standard antivirus is ineffective against custom ROKrat deployments. Utilize EDR to monitor for anomalous processes spawning from Office applications and unusual, sustained connections to cloud storage APIs.</li>\n<li><strong>Strict Access Controls:</strong> Implement Zero Trust principles, enforcing Multi-Factor Authentication (MFA) and limiting the execution of unauthorized binaries to prevent the malware from establishing a foothold, even if an exploit is successfully triggered.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "APT37",
    "Reaper",
    "Group123",
    "ROKrat"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.001",
    "T1059",
    "T1567.002",
    "T1125",
    "T1056.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T16:29:46Z",
  "type": "APT",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}