북한 해킹 단체 APT37(Reaper)에서 만든 악성코드-한국군사학논총(2025.3.26)
2025-03-31 • Sakai • APT37 Reaper malware disguised as Korean military studies journal material, March 26 2025 •
The report analyzes an APT37 Reaper lure that impersonates Korean military studies journal material to distribute RokRAT. The malicious file abuses PowerShell and a shortcut-based execution chain, with the report providing hashes including SHA-256 d182834a984c9f5b44ea0aca5786223a78138ff23d33362ab699c76bf6987261 and command-line artifacts that search for and invoke PowerShell from Windows system paths. The activity is consistent with social-engineering delivery against defense or policy-adjacent Korean targets, using a decoy academic theme while staging malware through script execution. Defenders should hunt for the listed hashes, suspicious LNK or document lures tied to Korean military research themes, and obfuscated PowerShell execution that extracts or launches RokRAT components.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2f431c4e65af9908d2182c6a093bf262 | 2025-03-27 | 2025-05-12 |
| DOMAIN | caller.3utilities.com | 2025-03-28 | 2025-04-10 |
| DOMAIN | blessdayservices.org | 2025-03-28 | 2025-04-10 |
| HASH | d4f15c892cc8c56fba4756526871b2b… | 2025-03-31 | 2025-03-31 |
| HASH | d182834a984c9f5b44ea0aca5786223… | 2025-03-31 | 2025-03-31 |