북한 APT 리퍼(Reaper)에서 만든 탈북민 사칭 한국해양수산연수원 타겟 인것으로 추측이 되는 악성코드-정보접근권.lnk(2024.11.1)
2024-11-04 • Sakai • Malware Created by North Korea's APT Reaper, Presumed to Impersonate a North Korean Defector and Target the Korea Institute of Maritime and Fisheries Technology - Information Access Rights.lnk (2024.11.1) •
The sample is attributed in the excerpt to Reaper/APT37 and uses a Windows LNK file with a defector-themed lure connected to the Korea Institute of Maritime and Fisheries Technology. The LNK masquerades with a Microsoft Edge icon, extracts and opens an embedded PDF decoy, writes caption.dat and elephant.dat into the temporary directory, creates a batch file, and deletes the original shortcut to reduce visible traces. The execution chain starts hidden PowerShell, loads script content from elephant.dat, XOR-decrypts the payload in caption.dat with the key "d", allocates executable memory through kernel32 APIs, and runs the payload via CreateThread. The body provides hashes for the LNK and pCloud API URLs used for file access, making the sample useful for tracking APT37/RoKRAT-style shortcut-based delivery and in-memory execution tradecraft against South Korea-related targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 89c0d2cc1e71b17449eec454161d60da | 2024-11-01 | 2025-02-19 |
| URL | https://api.pcloud.com/getfilel… | 2024-11-04 | 2024-11-04 |
| URL | https://api.pcloud.com/listfold… | 2024-11-04 | 2024-11-04 |
| HASH | 707e8cb56f32209ca837f2853801256… | 2024-11-01 | 2024-11-04 |
| HASH | e9528f09f1e58ffc308893087f4a8b7… | 2024-11-01 | 2024-11-04 |
| DOMAIN | telegram-df.org | 2024-10-30 | 2024-11-04 |