다중 플랫폼 겨냥의 진화 : APT37 그룹

2025-09-26 Piolink Evolution of Multi-Platform Targeting: APT37 Group

https://www.piolink.com/kr/service/Security-Analysis.php?bbsCode=security&vType=view&idx=165&page=2

Thumbnail for 다중 플랫폼 겨냥의 진화 : APT37 그룹

PIOLINK links recent APT37 activity to a shared C2 infrastructure used to operate Rustonotto, Chinotto, and FadeStealer against targets connected to North Korea policy, human rights, and South Korean interests. Initial access uses Windows shortcut files and CHM help files, including LNK payloads that extract an HWP decoy and a Rust-compiled Rustonotto backdoor from embedded AEL, BEL, and EOF markers. Rustonotto builds a victim identifier from the computer and user names, receives Base64-encoded Windows commands over HTTP, executes them, and returns encoded output to the C2 server. Supported commands enable file inventory, directory compression and upload, file exfiltration, downloads, registry edits, scheduled tasks, archive extraction, renaming, and deletion, while FadeStealer adds keylogging, screenshots, audio recording, device monitoring, and RAR-based data theft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d2b34b8bfafd6b17b1cf931bb3fdd3db 2025-09-08 2025-09-26
HASH 89986806a298ffd6367cf43f36136311 2025-09-08 2025-09-26
HASH 4caa44930e5587a0c9914bda9d240acc 2025-09-08 2025-09-26
HASH b9900bef33c6cc9911a5cd7eeda8e093 2025-09-08 2025-09-26
HASH 04b5e068e6f0079c2c205a42df8a3a84 2025-09-08 2025-09-26
HASH 3d6b999d65c775c1d27c8efa615ee520 2025-09-08 2025-09-26
HASH 7967156e138a66f3ee1bfce81836d8d0 2025-09-08 2025-09-26
HASH 77a70e87429c4e552649235a9a2cf11a 2025-09-08 2025-09-26
HASH 1c1136c12d0535f4b90e32aa36070682 2023-06-12 2025-09-26
HASH 1352abf9de97a0faf8645547211c3be7 2023-06-12 2025-09-26
HASH 3277e0232ed6715f2bae526686232e06 2023-06-12 2025-09-26
HASH 59804449f5670b4b9b3b13efdb296abb 2023-06-12 2025-09-26
HASH 3c475d80f5f6272234da821cc418a6f7 2023-06-12 2025-09-26
IPv4 172.93.181.249 2023-06-12 2025-09-26

Related Actors

Related Reports

« Back