북한 해킹 단체 Reaper(리퍼)에서 만든 악성코드-제20대_대통령선거_선거권자_개표참관인_공개_모집(최종).hwp(2022.8.15)
2024-04-09 • Sakai • Malware created by North Korean hacking group Reaper: twentieth presidential election observer recruitment HWP lure •
Reaper, also tracked as APT37, InkySquid, RedEyes, ScarCruft, and Group123, is described as using a malicious HWP-themed lure related to South Korea's twentieth presidential election and election-observer recruitment. The report frames the actor as a North Korea-linked espionage group focused on intelligence collection, reconnaissance, and cyber operations against government, military, enterprise, human-rights, and regional targets. The source provides malware-analysis context for defenders handling Korean document lures, HWP-themed filenames, and endpoint artifacts associated with the sample. Security teams should validate the hashes, execution behavior, and lure context in the archive before using the material for detection or response decisions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 5fec6e533fb9741997530a3d43b60ee… | 2024-03-01 | 2025-02-10 |
| HASH | 21b25271deb8075cd7e5cd2adec4c02… | 2024-04-09 | 2024-04-09 |
| HASH | 7fcda694bbd3640d7fe1cbdf4ef3751d | 2024-04-09 | 2024-04-09 |
| [email protected] | 2024-04-09 | 2024-04-09 | |
| URL | https://work3.b4a.app/download.… | 2024-04-09 | 2024-04-09 |
| URL | https://work3.b4a.app/download.… | 2024-04-09 | 2024-04-09 |
| [email protected] | 2024-03-01 | 2024-04-09 | |
| URL | https://work3.b4a.app | 2022-06-01 | 2024-04-09 |