다중 플랫폼 겨냥의 진화 : APT37 그룹
2025-09-26 • Piolink • Evolution of Multi-Platform Targeting: APT37 Group •
https://www.piolink.com/kr/service/Security-Analysis.php?bbsCode=security&vType=view&idx=165&page=2
PIOLINK links recent APT37 activity to a shared C2 infrastructure used to operate Rustonotto, Chinotto, and FadeStealer against targets connected to North Korea policy, human rights, and South Korean interests. Initial access uses Windows shortcut files and CHM help files, including LNK payloads that extract an HWP decoy and a Rust-compiled Rustonotto backdoor from embedded AEL, BEL, and EOF markers. Rustonotto builds a victim identifier from the computer and user names, receives Base64-encoded Windows commands over HTTP, executes them, and returns encoded output to the C2 server. Supported commands enable file inventory, directory compression and upload, file exfiltration, downloads, registry edits, scheduled tasks, archive extraction, renaming, and deletion, while FadeStealer adds keylogging, screenshots, audio recording, device monitoring, and RAR-based data theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d2b34b8bfafd6b17b1cf931bb3fdd3db | 2025-09-08 | 2025-09-26 |
| HASH | 89986806a298ffd6367cf43f36136311 | 2025-09-08 | 2025-09-26 |
| HASH | 4caa44930e5587a0c9914bda9d240acc | 2025-09-08 | 2025-09-26 |
| HASH | b9900bef33c6cc9911a5cd7eeda8e093 | 2025-09-08 | 2025-09-26 |
| HASH | 04b5e068e6f0079c2c205a42df8a3a84 | 2025-09-08 | 2025-09-26 |
| HASH | 3d6b999d65c775c1d27c8efa615ee520 | 2025-09-08 | 2025-09-26 |
| HASH | 7967156e138a66f3ee1bfce81836d8d0 | 2025-09-08 | 2025-09-26 |
| HASH | 77a70e87429c4e552649235a9a2cf11a | 2025-09-08 | 2025-09-26 |
| HASH | 1c1136c12d0535f4b90e32aa36070682 | 2023-06-12 | 2025-09-26 |
| HASH | 1352abf9de97a0faf8645547211c3be7 | 2023-06-12 | 2025-09-26 |
| HASH | 3277e0232ed6715f2bae526686232e06 | 2023-06-12 | 2025-09-26 |
| HASH | 59804449f5670b4b9b3b13efdb296abb | 2023-06-12 | 2025-09-26 |
| HASH | 3c475d80f5f6272234da821cc418a6f7 | 2023-06-12 | 2025-09-26 |
| IPv4 | 172.93.181.249 | 2023-06-12 | 2025-09-26 |