북한 해킹 단체 APT37(리퍼,Reaper)에서 만든 RokRAT 악성코드-북한이탈 주민의 성공적인 남한정착을 위한 아카데미 운영.lnk(2025.7.21)
2025-08-21 • Sakai • RokRAT Malware Created by North Korean Hacking Group APT37 (Reaper) - Academy Operation for Successful Resettlement of North Korean Defectors in South Korea.lnk (2025.7.21) •
A Korean-language analysis attributes a malicious LNK lure to APT37/Reaper and identifies RokRAT delivery through a decoy about an academy for successful resettlement of North Korean defectors in South Korea. The shortcut searches for PowerShell, locates an oversized LNK of a specific size, extracts an embedded HWP decoy, encrypted executable data, a string file, and a batch script from fixed offsets, then executes the generated files from the temporary directory. The payload is described as XOR-encrypted with key 0x35 and loaded in memory through dynamically declared Windows APIs including GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject. The lure theme and decoy content suggest targeting of people connected to North Korea defector, unification, or security-policy communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 443a00feeb3beaea02b2fbcd4302a3c9 | 2025-08-03 | 2026-01-14 |
| HASH | 65f79b9fa476e9aafec16a7995b39c7… | 2025-08-21 | 2025-08-21 |
| HASH | ccb6ca4cb385db50dad2e3b7c68a90d… | 2025-08-21 | 2025-08-21 |
| DOMAIN | ystem.io | 2023-09-26 | 2025-08-21 |