"북한지 기고문"을 위장하여 유포된 LNK 악성코드
2024-03-21 • Secu I • start /min C:\Windows\SysWow64\WindowsPowerShell\v1.0\powershell.exe -windowstyle hidden " •
Secui STIC reports an APT37-style LNK campaign that used a North Korea-themed contribution article lure to deliver RokRAT. The ZIP archive contained normal PDF decoys and a malicious LNK file; when opened, the shortcut launched hidden PowerShell, extracted embedded files into the temp directory, and ran a batch file and script chain. The script loaded shellcode from Public.dat, decoded data with XOR key 0x29, and executed RokRAT, a known malware family that uses cloud services such as Dropbox, pCloud, and Yandex for C2. STIC notes that this LNK and PowerShell technique has been used by APT37 against Korean organizations for years and lists hashes for the ZIP, LNK, and RokRAT payload.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cbc777d1e018832790482e6fd82ab18… | 2024-03-21 | 2024-09-13 |
| HASH | 4f5d8bb87b68b943c1e4f05c12a8c08… | 2024-03-21 | 2024-09-13 |
| HASH | e914f39c7800f87e99ca4821c7a6d4a… | 2024-03-21 | 2024-09-13 |