"북한지 기고문"을 위장하여 유포된 LNK 악성코드

2024-03-21 Secu I start /min C:\Windows\SysWow64\WindowsPowerShell\v1.0\powershell.exe -windowstyle hidden "

https://stic.secui.com/main/main/threatInfo?id=215

Thumbnail for "북한지 기고문"을 위장하여 유포된 LNK 악성코드

Secui STIC reports an APT37-style LNK campaign that used a North Korea-themed contribution article lure to deliver RokRAT. The ZIP archive contained normal PDF decoys and a malicious LNK file; when opened, the shortcut launched hidden PowerShell, extracted embedded files into the temp directory, and ran a batch file and script chain. The script loaded shellcode from Public.dat, decoded data with XOR key 0x29, and executed RokRAT, a known malware family that uses cloud services such as Dropbox, pCloud, and Yandex for C2. STIC notes that this LNK and PowerShell technique has been used by APT37 against Korean organizations for years and lists hashes for the ZIP, LNK, and RokRAT payload.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cbc777d1e018832790482e6fd82ab18… 2024-03-21 2024-09-13
HASH 4f5d8bb87b68b943c1e4f05c12a8c08… 2024-03-21 2024-09-13
HASH e914f39c7800f87e99ca4821c7a6d4a… 2024-03-21 2024-09-13

Related Actors

Related Reports

« Back