북한 해킹 단체 APT37(리퍼,Reaper)에서 만든 RokRAT 악성코드-북한이탈 주민의 성공적인 남한정착을 위한 아카데미 운영.lnk(2025.7.21)

2025-08-21 Sakai RokRAT Malware Created by North Korean Hacking Group APT37 (Reaper) - Academy Operation for Successful Resettlement of North Korean Defectors in South Korea.lnk (2025.7.21)

https://wezard4u.tistory.com/429575

Thumbnail for 북한 해킹 단체 APT37(리퍼,Reaper)에서 만든 RokRAT 악성코드-북한이탈 주민의 성공적인 남한정착을 위한 아카데미 운영.lnk(2025.7.21)

A Korean-language analysis attributes a malicious LNK lure to APT37/Reaper and identifies RokRAT delivery through a decoy about an academy for successful resettlement of North Korean defectors in South Korea. The shortcut searches for PowerShell, locates an oversized LNK of a specific size, extracts an embedded HWP decoy, encrypted executable data, a string file, and a batch script from fixed offsets, then executes the generated files from the temporary directory. The payload is described as XOR-encrypted with key 0x35 and loaded in memory through dynamically declared Windows APIs including GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject. The lure theme and decoy content suggest targeting of people connected to North Korea defector, unification, or security-policy communities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 443a00feeb3beaea02b2fbcd4302a3c9 2025-08-03 2026-01-14
HASH 65f79b9fa476e9aafec16a7995b39c7… 2025-08-21 2025-08-21
HASH ccb6ca4cb385db50dad2e3b7c68a90d… 2025-08-21 2025-08-21
DOMAIN ystem.io 2023-09-26 2025-08-21

Related Actors

Related Reports

« Back