Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 23:46:37 UTC Home > List all groups > List all tools > List all groups using tool Nokki Tool: Nokki Names Nokki Category Malware Type Backdoor, Info stealer Description Nokki is a RAT type malware which is believe to evolve from Konni RAT. This malware has been tied to attacks containing politically-motivated lures targeting Russian and Cambodian speaking individuals or organizations. Researchers discovered a tie to the threat actor group known as Reaper also known as APT37. Information MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 14 May 2020 Download this tool card in JSON format All groups using tool Nokki Changed Name Country Observed APT groups Reaper, APT 37, Ricochet Chollima, ScarCruft 2012-Mar 2025 1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bf4470c0-bb0f-49d5-8316-c852411c6570 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bf4470c0-bb0f-49d5-8316-c852411c6570 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=bf4470c0-bb0f-49d5-8316-c852411c6570 Page 2 of 2