Scarcruft
Overview
Executive Summary
ScarCruft (also known widely as APT37, Reaper, or Group123) is a highly capable, state-sponsored Advanced Persistent Threat (APT) group believed to operate out of North Korea. Active since at least 2012, ScarCruft is primarily focused on cyber-espionage and intelligence gathering, specifically targeting South Korean government entities, defectors, journalists, and defense contractors across East Asia and the Middle East.Technical Capabilities and Attack Lifecycle
ScarCruft is known for its agility and rapid adoption of newly disclosed zero-day vulnerabilities (particularly in Adobe Flash and Microsoft Office) to facilitate initial access. The group's operational lifecycle is heavily focused on stealth and data extraction:- Targeted Spear-Phishing: Campaigns begin with meticulously crafted emails containing weaponized documents relevant to the target's geopolitical interests (e.g., inter-Korean relations). These documents exploit vulnerabilities to silently drop the initial payload.
- Custom Tooling (ROKrat/DogCall): ScarCruft heavily relies on a custom, sophisticated Remote Access Trojan (RAT) known as ROKrat (or DogCall). This malware is engineered for deep persistence and extensive intelligence gathering, including keystroke logging, audio recording via the microphone, and stealthy screen captures.
- Covert Exfiltration: To bypass network perimeter defenses, ScarCruft frequently utilizes legitimate cloud services (like Yandex, Dropbox, or pCloud) as their command-and-control (C2) infrastructure. Stolen data is encrypted and silently uploaded to these trusted domains, making the exfiltration traffic incredibly difficult to distinguish from normal user activity.
Threat Impact
A ScarCruft compromise is a severe national security incident. The group's primary objective is the theft of classified political, military, and strategic intelligence, which directly supports the objectives of the North Korean state apparatus.Defense and Resilience Strategies
- Rapid Patch Management: Because ScarCruft is known to rapidly weaponize zero-day and N-day vulnerabilities, organizations must maintain an aggressive patching cadence for all operating systems and third-party applications (especially Office and browsers).
- Behavioral Analytics and EDR: Standard antivirus is ineffective against custom ROKrat deployments. Utilize EDR to monitor for anomalous processes spawning from Office applications and unusual, sustained connections to cloud storage APIs.
- Strict Access Controls: Implement Zero Trust principles, enforcing Multi-Factor Authentication (MFA) and limiting the execution of unauthorized binaries to prevent the malware from establishing a foothold, even if an exploit is successfully triggered.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1566.001 T1059 T1567.002 T1125 T1056.001
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1056.001: Implement Endpoint Detection and Response (EDR) to monitor for suspicious API calls related to keystroke interception. Enforce Multi-Factor Authentication (MFA) to render stolen passwords useless.
- T1059: Restrict execution of scripting languages such as PowerShell, VBScript, or Python to authorized administrators. Enforce Script Block Logging.
- T1125: Restrict access to local camera or microphone APIs. Utilize endpoint protection that monitors hardware access.
- T1566.001: Scan email attachments for malicious macros, scripts, or suspicious archive files.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_SCARCRUFT {
meta:
description = "Detects Scarcruft (trojan)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "scarcruft" ascii wide nocase
$s2 = "apt37" ascii wide nocase
$s3 = "reaper" ascii wide nocase
$s4 = "group123" ascii wide nocase
$s5 = "rokrat" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Scarcruft Activity
id: 5c1be218452c7a40837b7b7aaf4f4322
status: experimental
description: Detects generic indicators of the scarcruft malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*scarcruft*"
- "*apt37*"
- "*reaper*"
- "*group123*"
- "*rokrat*"
condition: selection
level: mediumReferences & External Analysis
- Search "scarcruft" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Scarcruft Trojan from Windows?
Manual removal of Scarcruft is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Scarcruft a virus or a Trojan?
Scarcruft is classified as a Trojan. Unlike traditional viruses that infect files, modern malware like Scarcruft typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Scarcruft infection?
Symptoms of Scarcruft can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: trojan)
Explore other malware families in the same category:
Protect Your Network Against Trojans
Want to prevent Scarcruft and similar threats from compromising your organization? Read our comprehensive defensive guide: Banking Trojan Protection.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/scarcruft.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.