대북 관계자를 타켓팅 하는 APT 37(Reaper,리퍼)에서 만든 악성코드-김X성강의자료.lnk(2024.12.06)
2024-12-09 • Sakai • Malware Created by APT37 (Reaper) Targeting People Involved in North Korea-Related Affairs - Kim X-sung Lecture Materials.lnk (2024.12.06) •
APT37 is linked to a large malicious LNK file disguised as lecture material for people connected to North Korea issues. The shortcut contains embedded PDF, BAT, and DAT data and uses PowerShell to locate the LNK, extract a PDF, write vivo.dat, oppo.dat, and huawei.bat into the temporary directory, execute the batch file, and delete the original shortcut. The follow-on script runs hidden 32-bit PowerShell, reads oppo.dat as a script block, XOR-decodes vivo.dat with the key h, allocates executable memory, changes memory protection, and starts the decoded payload through kernel32 APIs. The source provides hashes including SHA-256 d9e3eba6067eec0aa32214b2a9811f4b579b66b34fe4e5bff4d754102dffdb91, making the sample useful for detecting LNK-based APT37 delivery and in-memory payload execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | stem.io | 2024-05-22 | 2025-05-13 |
| HASH | 2fa8f5f95577db335e649d5361c845b0 | 2024-12-09 | 2024-12-09 |
| HASH | d9e3eba6067eec0aa32214b2a9811f4… | 2024-12-09 | 2024-12-09 |
| HASH | c8bb4f1ebeafd00cc6b73e2cf265c18… | 2024-12-09 | 2024-12-09 |