Geek-Guy.com

Threat Actor Dossier: APT37 (Earth Manticore) 2026

Advanced Persistent Threat 37 – North Korean State-Sponsored

Executive Summary

APT37 (also known as Earth Manticore, APT37, Earth Manticore, G0012) is a North Korean state-sponsored advanced persistent threat group primarily focused on government and military targeting, espionage, and critical infrastructure operations. This report covers their operations as of 2026, including their recent campaigns, tools, TTPs, and target sectors.

Threat Actor Dossier: APT41 (BARIUM/BRASS TYPHOON/WICKED PANDA)

Basic Information

  • Name: APT37 (Earth Manticore)
  • Aliases: APT37, Earth Manticore, G0012
  • MITRE ATT&CK Group ID: G0012
  • Country of Origin: North Korea
  • Threat Level: HIGH
  • Primary Motivation: State-sponsored espionage, government and military targeting

Recent Operations (2025-2026)

South Korean Government and Military (2025-2026):

  • South Korean government targeting
  • Military organization operations
  • Defense contractor espionage
  • Research institute compromise

Government Think Tanks (2025-2026):

  • Government think tank operations
  • Policy research institution targeting
  • International organization operations
  • Diplomatic mission targeting

Primary Tools:

  • Cobalt Strike (primary post-exploitation)
  • Custom malware (Earth Manticore framework)
  • Spearphishing campaigns
  • Zero-day exploitation
  • Credential dumping (Mimikatz, BloodHound)

TTPs (MITRE ATT&CK Mapping)

Initial Access:

  • Phishing (Spearphishing Link, Spearphishing Attachment)
  • Exploit publicly available vulnerabilities
  • Supply chain compromise

Execution:

  • Browser Execution
  • PowerShell
  • Command and Scripting Interpreter

Persistence:

  • Boot/Logon Autostart
  • Accessibility Features
  • Lateral Tool Transfer

Privilege Escalation:

  • Exploitation for Privilege Escalation
  • Abuse Elevation Control Mechanism

Defense Evasion:

  • Indicator Removal
  • File and Directory Permissions Modification
  • Obfuscated Files or Information

Credential Access:

  • Credential Dumping (LSASS Memory)
  • Remote Service Discovery

Discovery:

  • Active Directory Enumeration
  • Network Service Discovery

Lateral Movement:

  • Remote Services (RDP, SMB)
  • Remote Services (SMB)

Collection:

  • Data from Local System
  • Data from Network

Exfiltration:

  • Exfiltration Over C2 Channel
  • Exfiltration Over Alternative Protocol

Known Campaigns (2025-2026)

Operation 1 (2025):

  • Target: South Korean government and military
  • Impact: Political influence, information warfare
  • Tools: Cobalt Strike, custom malware

Operation 2 (2025):

  • Target: Government think tanks
  • Impact: Policy research data theft
  • Tools: Cobalt Strike, Mimikatz

Operation 3 (2026):

  • Target: International organizations
  • Impact: Diplomatic mission compromise
  • Tools: Cobalt Strike, spearphishing

Threat Assessment

Threat Level: HIGH

Primary Targets:

  • South Korean government
  • Military organizations
  • Government think tanks
  • International organizations

Capabilities:

  • Advanced persistent threat
  • Government and military targeting
  • Multi-vector attacks
  • Long-term persistence
  • Information warfare

Sources

  • Brandefense
  • NSFOCUS
  • CIONet
  • CrowdStrike Threat Intelligence
  • Mandiant Reports
  • FortiGuard Labs
  • CISA Advisories
  • National Intelligence Service

Report Generated: 2026-06-10
 
 Intelligence Freshness: Current (as of June 2026)
 
 Classification: Unclassified