APT37, also known as Reaper, ScarCruft, or Ricochet Chollima, is a North Korean state-sponsored cyber espionage group that emerged around 2012. It has progressively expanded its operational scope and sophistication, notably since 2017. The group is assessed with high confidence to operate under the Reconnaissance General Bureau (RGB), North Korea's primary intelligence agency. Its core motivation is cyber espionage, primarily focused on intelligence gathering to support the DPRK's strategic military, political, and economic interests, though recent activities indicate a shift towards financially motivated operations, including the deployment of ransomware. APT37 is distinguished by its consistent ability to rapidly incorporate zero-day vulnerabilities in common software like Hangul Word Processor, Adobe Flash, and Internet Explorer into its campaigns, coupled with its use of customized malware families and strategic web compromises. While primarily targeting South Korea, its operations