북한 시장 물가 분석 문서 등으로 위장된 공격 사례
2023-12-29 • Genians • Cases of attacks disguised as North Korean market price analysis documents, etc. •
Attachments
Genians reported APT37 activity using malicious HWP, HWPX, LNK, XLSX, and DOCX files, including lures disguised as North Korean market-price analysis documents. The campaign abused OLE objects embedded in Korean document formats to contact attacker-controlled C2 servers and trigger exploit commands. Genians connected the activity to earlier APT37 LNK and CVE-2022-41128-themed operations and emphasized the need for endpoint detection against unknown or newly combined document-exploitation techniques.
Related Actors
Related Reports
Shares tag: APT37 • Same author: Genians • Published within a month
Shares tags: APT37, CVE-2022-41128
2025-02-10 •
60% Match
Targeted Threats Research - South & North Korea (a breakdown of 3 years of threat research in Korea)
0x0v1
Shares tags: APT37, CVE-2022-41128
Shares tag: APT37 • Same author: Genians
Shares tag: APT37 • Published within a month
Shares tags: APT37, CVE-2022-41128