대북관계자를 노리는 북한 해킹 단체 리퍼(Reaper)에서 만든 악성코드-국가정보와 방첩 원고.lnk(2025.6.3)

2025-06-09 Sakai Malware Created by North Korean Hacking Group Reaper Targeting People Involved in North Korea Affairs - National Intelligence and Counterintelligence Manuscript.lnk (2025.6.3)

https://wezard4u.tistory.com/429506

Thumbnail for 대북관계자를 노리는 북한 해킹 단체 리퍼(Reaper)에서 만든 악성코드-국가정보와 방첩 원고.lnk(2025.6.3)

Reaper/APT37 is described using a malicious LNK file named “National Intelligence and Counterintelligence Manuscript.lnk” against South Korea–focused North Korea watchers. The targeted audience includes human rights groups, journalists covering North Korea, defectors, and university professors, consistent with RoKRAT-style targeting. The shortcut runs PowerShell to extract embedded HWP decoy content and payload files from fixed offsets, drops ttf01.dat, ttf02.dat, and a BAT script into the temp directory, and deletes the original LNK. The payload flow uses XOR decryption with key 3, allocates executable memory, changes it to RWX with VirtualProtect, writes shellcode with Marshal.WriteByte, and runs it through CreateThread. The excerpt provides hashes for the LNK and shows use of hidden 32-bit PowerShell execution, making the sample useful for detection and DPRK-focused intrusion tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f6d72abf9ca654a20bbaf23ea1c10a55 2025-06-09 2025-08-29
HASH 90bf1f20f962d04f8ae3f936d0f9046… 2025-06-09 2025-06-09
HASH 543e3b4b74257c3ffcd45dcdd8c8424… 2025-06-09 2025-06-09

Related Actors

Related Reports

« Back