Threat Actor
APT37
- First Reported
- Jul 12, 2026
- Latest Reported
- Aug 9, 2026
Reported Context (2)
- Separately cited for its previously disclosed use of an internally developed LNK creation tool in attacks; the report does not identify it as the operator of the activity analyzed here. Kimsuky Uses AI-Generated Decoys and Experiments with Local LLMs
- Genians assessed the attack as highly likely to have been conducted by APT37, based on malware, cloud C2, account, infrastructure, and TTP correlations; it cautioned that code similarity alone is insufficient for attribution. Operation Capsule Vault: Analysis of a RokRAT Attack Chain Using EMBED_PAYLOAD_v2
Malware (2)
People (1)
Threat Actors (1)
MITRE ATT&CK (20)
Vendors (1)
Products (6)
Tools (5)
Industries (7)
Countries (5)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.