북한 해킹 단체 Reaper(리퍼)에서 만든 악성코드-제20대_대통령선거_선거권자_개표참관인_공개_모집(최종).hwp(2022.8.15)

2024-04-09 Sakai Malware created by North Korean hacking group Reaper: twentieth presidential election observer recruitment HWP lure

https://wezard4u.tistory.com/6787

Thumbnail for 북한 해킹 단체 Reaper(리퍼)에서 만든 악성코드-제20대_대통령선거_선거권자_개표참관인_공개_모집(최종).hwp(2022.8.15)

Reaper, also tracked as APT37, InkySquid, RedEyes, ScarCruft, and Group123, is described as using a malicious HWP-themed lure related to South Korea's twentieth presidential election and election-observer recruitment. The report frames the actor as a North Korea-linked espionage group focused on intelligence collection, reconnaissance, and cyber operations against government, military, enterprise, human-rights, and regional targets. The source provides malware-analysis context for defenders handling Korean document lures, HWP-themed filenames, and endpoint artifacts associated with the sample. Security teams should validate the hashes, execution behavior, and lure context in the archive before using the material for detection or response decisions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5fec6e533fb9741997530a3d43b60ee… 2024-03-01 2025-02-10
HASH 21b25271deb8075cd7e5cd2adec4c02… 2024-04-09 2024-04-09
HASH 7fcda694bbd3640d7fe1cbdf4ef3751d 2024-04-09 2024-04-09
EMAIL [email protected] 2024-04-09 2024-04-09
URL https://work3.b4a.app/download.… 2024-04-09 2024-04-09
URL https://work3.b4a.app/download.… 2024-04-09 2024-04-09
EMAIL [email protected] 2024-03-01 2024-04-09
URL https://work3.b4a.app 2022-06-01 2024-04-09

Related Actors

Related Reports

« Back