SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

APT37

🏛️ Nation-StateLast active: 2026-07-31First seen: 2018-04-18G0067
1
linked CVEs
Also known as
APT 37Group 123Group123InkySquidOperation DaybreakOperation ErebusReaper GroupReaperRed EyesRicochet ChollimaScarCruftVenus 121ATK4G0067Moldy PiscesAPT-C-28TEMP.Reaper
Targeted industries
GovernmentPrivate sector
APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its targeting beyond the Korean peninsula to include Japan, Vietnam and the Middle East, and to a wider range of industry verticals, including chemicals, electronics, manufacturing, aerospace, automotive and healthcare entities
Source: misp_galaxy · Collected: 2026-08-08
⚡ Vulnerabilities & Exploits1 CVE
threat_actor_cve → cves / exploits.cve_ids
CVE-2016-4171
suspected

Unspecified vulnerability in Adobe Flash Player allows for remote code execution.

KEV
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used29 techniques
Across 10 tactics
Discovery4 techniques
Execution9 techniques
T1053.005Scheduled Task
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The […
T1059Command and Scripting Interpreter
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common featu…
T1059.003Windows Command Shell
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows…
T1059.005Visual Basic
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as [Component Object Model](https://a…
T1059.006Python
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactiv…
T1106Native API
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, suc…
T1203Exploitation for Client Execution
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior.…
T1204.002Malicious File
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This us…
T1559.002Dynamic Data Exchange
Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server protocol for one-time and/or continuous inter-process communication (IPC) between applicat…
Privilege Escalation4 techniques
Stealth4 techniques
🛰️ Infrastructure & IOCs48
domainwebhostingkorea.com2026-07-15
domainwww.novel21.co.kr2026-07-15
domainfe01.co.kr2026-07-15
md53715092aa00f380cefe8b4d2eddb7d082026-07-15
md57cef19f9c4480adac0cd4702ff98f46c2026-07-15
md57eb9cee1f696727752169f25cf79a3382026-07-15
md5b6b0602310bb2d4360c52685119aac1b2026-07-15
urlhttp://www.novel21.co.kr/data/editor/2110/index.php2026-07-15
domainnovel21.co.kr2026-07-15
domaincrwellfood.com2026-07-15
ip5.180.208.572026-07-13
ip5.180.208.602026-07-13
ip160.238.37.952026-07-13
ip89.147.101.1972026-07-13
ip160.238.37.1002026-07-13
md5e5c9bb3938f2a24e755ee39073fc3aca2026-07-13
ip89.187.161.2202026-07-13
sha1b06110e0feb7592872e380b7e3b8f77d80dd11082026-05-05
sha1fc0c691db7e2d2bd3b0b4c1e24d18df72168b7d92026-05-05
ip114.108.128.1572026-05-05
ip211.239.117.1172026-05-05
ip221.143.43.2142026-05-05
ip222.231.2.202026-05-05
ip222.231.2.232026-05-05
ip222.231.2.412026-05-05
ip39.106.249.682026-05-05
urlhttp://sqgame.com.cn/sqybhs.apk2026-05-05
urlhttp://sqgame.com.cn/ybht.apk2026-05-05
urlhttp://xiazai.sqgame.com.cn/dating/20240429.zip2026-05-05
urlhttps://ipinfo.io/json2026-05-05
urlhttps://www.sqgame.net2026-05-05
urlhttps://www.sqgame.net/games/gamedownload.aspx2026-05-05
domain1980food.co.kr2026-05-05
domaincndsoft.co.kr2026-05-05
domaincolorncopy.co.kr2026-05-05
domaininodea.com2026-05-05
domainsejonghaeun.com2026-05-05
domainsqgame.com.cn2026-05-05
domainswr.co.kr2026-05-05
domainwww.lawwell.co.kr2026-05-05
sha101a33066fbc6253304c92760916329abd50c31912026-05-05
sha103e3ece9f48cf4104aafc535790ca2fb3c6b26cf2026-05-05
sha12b81f78ec4c3f8d6cf8f677d141c5d13c35333af2026-05-05
sha1409c5acaed587f62f7e23da47f72c4d9ec3144d92026-05-05
sha159a9b9d47ae36411b277544f25ad2cc955d8dd2c2026-05-05
sha17356d7868c81499fb4e720f7c9530e5763b4c1d02026-05-05
sha195bdb94f6767a3cce6d92363bbf5bc84b786bdb02026-05-05
md5a8fe823d451d636d0a0366c0629ef5c32026-05-05
📰 Threat Intel Coverage4
Digest reports mentioning this actor (incl. aliases)
ESET APT Activity Report Q4 2025–Q1 2026matched as ScarCruft2026-05-28
A rigged game: ScarCruft compromises gaming platform in a supply-chain attackmatched as Reaper2026-05-05
A rigged game: ScarCruft compromises gaming platform in a supply-chain attackmatched as ScarCruft2026-05-05
ZDI-CAN-25373: Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaignsmatched as APT372025-03-21