Skip to content
June 19, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • North Korea hacker group APT37 is using zero-day vulnerability to attack Japan, Vietnam and the Middle East countries
  • Cyber Security

North Korea hacker group APT37 is using zero-day vulnerability to attack Japan, Vietnam and the Middle East countries

Do Son February 27, 2018 2 minutes read
Add as a preferred
source on Google

On February 2, 2018, a research team from FireEye, a cyber-security company, published a blog detailing how a hacker group suspected of being associated with North Korea used the Adobe Flash Zero-Day Vulnerability (CVE-2018-4878) to launch a network espionage. Now, FireEye tracks the operating organization behind the event as APT37 (aka “Reaper”).

According to FireEye’s analysis of recent APT37 activities, FireEye said the organization is expanding its scope of business and increasing sophistication, including more zero-day vulnerabilities and the use of malware such as hard disk erasing devices.

FireEye strongly believes that APT37’s activities are linked to the DPRK because the interests pursued by the DPRK based on the malware it uses are shared with the common interests pursued by North Korea. In addition, activities conducted by the APT37 are also highly consistent with the activities of the publicly reported hacker groups Scarcruft and Group123.

APT37 has been active at least since 2012, initially focusing its activities in South Korea. However, since 2017, its activities have been extended to Japan, Vietnam and the Middle East. Its areas of involvement also extend to various vertical industries, including chemicals, electronics, manufacturing, aerospace, automotive and healthcare.

 

The reason why APT37 attack complexity is being strengthened, which is mainly reflected in the use of loopholes. In the attacks launched before APT37, they mainly used vulnerabilities in the Hangul Word Processor (HWP). However, from their recent activity, they already have the ability to leverage Adobe Flash and other zero-day vulnerabilities and can quickly exploit the vulnerability once it is announced. As confirmed by FireEye, at least since November 2017, APT37 has begun utilizing the Adobe Flash Zero-day Vulnerability CVE-2018-4878 to distribute malware.

 

FireEye emphasized that they had underestimated the APT37’s ability before. In the early days of APT37, they used only those malware used for initial intrusion or disclosure. However, in the follow-up activities, they have begun to use a variety of custom or self-developed malware. In addition to espionage, some malicious software is also devastating, such as hard disk eraser.

Read the full report

APT37 (REAPER) The Overlooked North Korean Actor

 

Related coverage

  • China-Backed Flax Typhoon APT Maintained Year-Long Access by Turning ArcGIS SOE into Web Shell Backdoor
  • ThreatMon Revealed APT41’s Stealthy PowerShell Backdoor
  • Black-Hat SEO Poisoning Indian Government and Financial Websites
  • Report: DDoS Attacks Decline, But Large-Scale Threats Surge
  • Citrix NetScaler Under Siege: Significant Increase in Brute Force Attacks Observed

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: APT37

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-56209CVSS 9.1
    An arbitrary address write vulnerability was found in libaom, the reference AV1...
  • CVE-2026-55884
    ## Summary The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints...
  • CVE-2026-9142CVSS 9.1
    There is an insecure default credentials vulnerability in NI grpc-device when TLS...
  • CVE-2026-54051CVSS 9.9
    ## Summary The agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`),...
  • CVE-2026-48137CVSS 9.1
    There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband...
  • CVE-2026-50242CVSS 10.0
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass...
  • CVE-2026-56142CVSS 9.6
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation...
  • CVE-2026-56141CVSS 9.8
    In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover...
  • CVE-2026-54414CVSS 9.8
    FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload...
  • CVE-2026-7515CVSS 9.8
    The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.