북한 APT 리퍼(Reaper)에서 만든 악성코드-동북공정(미국의회조사국(CRS Report).pdf.lnk(2024.4.3)
2025-01-01 • Sakai • Malware Created by North Korea's APT Reaper - Northeast Project (U.S. Congressional Research Service CRS Report).pdf.lnk (2024.4.3) •
A Korean analysis attributes a malicious LNK file disguised as a CRS report PDF to North Korea's Reaper, also known as APT37. The shortcut searches for PowerShell, locates an embedded payload by file size, extracts and opens a decoy PDF, then writes panic.dat under the public directory and para.dat plus price.bat under the temp directory. The follow-on PowerShell logic loads panic.dat into executable memory with kernel32 APIs such as GlobalAlloc, VirtualProtect and CreateThread. The lure and loader details make the sample relevant to APT37 tracking, especially Korean-language document themes and script-based execution from LNK containers.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0c61effe0c06d57835ead4a574dde99… | 2025-01-01 | 2025-01-01 |
| HASH | b1025baa59609708315326fe4279d81… | 2024-09-13 | 2025-01-01 |
| HASH | 358122718ba11b3e8bb56340dbe94f51 | 2024-04-23 | 2025-01-01 |