Skip to content


SLOWDRIFT is a backdoor used by APT37 against academic and strategic victims in South Korea. 1

Item Value
ID S0218
Associated Names
Version 1.1
Created 18 April 2018
Last Modified 30 March 2020
Navigation Layer View In ATT&CK® Navigator

Techniques Used

Domain ID Name Use
enterprise T1105 Ingress Tool Transfer SLOWDRIFT downloads additional payloads.1
enterprise T1082 System Information Discovery SLOWDRIFT collects and sends system information to its C2.1
enterprise T1102 Web Service -
enterprise T1102.002 Bidirectional Communication SLOWDRIFT uses cloud based services for C2.1

Groups That Use This Software

ID Name References
G0067 APT37 1


Back to top