logo

Peeking at Reaper’s surveillance operations

ID: e82bd348-bed7-5762-94b8-97739807d09c

STIX ID: report--e82bd348-bed7-5762-94b8-97739807d09c

Feed Name: Sekoia.com

Threat Score
90/100

Date Published: 2023-03-16

Date Updated: 2026-07-20

...
...

SEKOIA.IO discovered Reaper (aka APT37) Command-and-Control infrastructure exposing hosted implants and victims' exfiltrated data; their analysis documents credential-harvesting phishing (including 2FA bypass using Ably/PubNub), CHM-based infection vectors that drop PowerShell backdoors, and multiple Chinotto Windows DLL variants performing screenshots, keylogging and targeted data collection/exfiltration. The report includes extensive IoCs (file hashes, URLs, IPs), YARA rules, and attributes the activity to Reaper with high confidence, assessing it as a targeted cyberespionage campaign against North Korean defectors and related civil-society actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.