韩美大规模联合军演挑衅升级朝方 APT 组织近期攻击活动分析
2023-09-12 • Knownsec • Large-scale joint military exercises between South Korea and the United States escalate the provocation. Analysis of recent attacks by North Korean APT organizations •
Knownsec 404 researchers observed a sharp rise in North Korean APT activity against South Korean targets during the August 2023 Ulchi Freedom Shield joint exercises. The report says more than 80 samples were captured during the exercises and more than 200 deduplicated samples by early September, with APT37 accounting for most of the activity and LNK or CHM files commonly used as first-stage delivery. It documents APT37 use of oversized LNK packaging and two Chinotto variants, while Konni activity used LNK and CHM lures, VBS and BAT scripts, bitsadmin and certutil, CAB payloads, Run-key persistence, and collection of desktop file lists, IP data, and system information. The authors assess the activity as broad intelligence collection against South Korea, with both APT37 and Konni changing chains and obfuscation to maintain operational stability after public disclosures.