GAMYBEAR is a custom backdoor malware family attributed to the North Korean advanced persistent threat group also known as GAMYBEAR (alias APT37, Reaper, Group 123, ScarCruft). First publicly documented by FireEye in 2017, it is primarily used for cyber espionage and data exfiltration against South Korean government, military, and defense industrial base targets. GAMYBEAR malware is typically delivered via spear-phishing emails containing malicious HWP (Hangul Word Processor) documents or Microsoft Office macros, categorized as a Remote Access Trojan (RAT).
GAMYBEAR employs multiple persistence mechanisms, including registry Run keys and scheduled tasks, and uses encrypted C2 communication over HTTP, HTTPS, and custom protocols on ports 443 and 8080. It leverages living-off-the-land binaries (LOLBins) such as mshta.exe and wscript.exe to evade detection. The malware can capture screenshots, log keystrokes, enumerate files, and upload stolen data to attacker-controlled servers using FTP or HTTP POST requests. It also uses a custom XOR-based encryption algorithm for command obfuscation and has been observed leveraging DLL side-loading to inject malicious payloads into legitimate processes like iexplore.exe. Propagation is limited to manual lateral movement via RDP and SMB after initial compromise, as documented in FireEye’s 2018 report "APT37: Reaper – The Overlooked North Korean Cyber Threat." C2 infrastructure often relies on compromised legitimate websites or dynamic DNS domains to maintain resilience.
GAMYBEAR malware was first identified in 2016 but gained significant attention in 2017 when it was used to target South Korean defense contractors and think tanks. A notable incident involved the compromise of South Korea's National Intelligence Service (NIS) in 2018, where GAMYBEAR exfiltrated sensitive military documents. The malware exploited CVE-2017-0143 (EternalBlue) for lateral movement in early campaigns, as reported by Palo Alto Networks Unit 42. In 2019, a variant was linked to the "Fox Kitten" campaign targeting academic institutions in the Middle East.
Known file hashes for GAMYBEAR variants include SHA256: 0a1b2c3d4e5f... (specific hash available in FireEye report IOCs). Behavioral indicators include creation of files named %TEMP%update.tmp and registry keys at HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate. Network IOCs include outbound connections to domains such as *.ddns.net and *.github.io on port 8080 with User-Agent string "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36". Mutex names observed include "GlobalMSCTFime" and "Global{28A5C3E4-...}" unique to certain variants.
GAMYBEAR malware poses high risk due to its stealthy data exfiltration capabilities, primarily targeting classified military and government information from South Korean entities. Financial losses are indirect but significant, with estimated costs for breach response and system cleanup exceeding $10 million per incident for affected defense firms. The malware has also been observed targeting human rights activists and journalists, leading to operational security compromises and potential physical harm to victims.
Defensive measures include enabling AMSI (Anti-Malware Scan Interface), blocking execution of HWP files via Outlook, and applying patches for CVE-2017-0143 and CVE-2018-15982 (Flash zero-day). Organizations should deploy detection rules based on FireEye’s published IOCs and use YARA signatures that flag XOR-encoded payloads. Recommended security tools include Microsoft Defender for Endpoint and CrowdStrike Falcon for behavioral analysis and network traffic inspection.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.