북한 APT 리퍼(Reaper)에서 만든 탈북민 사칭 한국해양수산연수원 타겟 인것으로 추측이 되는 악성코드-정보접근권.lnk(2024.11.1)

2024-11-04 Sakai Malware Created by North Korea's APT Reaper, Presumed to Impersonate a North Korean Defector and Target the Korea Institute of Maritime and Fisheries Technology - Information Access Rights.lnk (2024.11.1)

https://wezard4u.tistory.com/429316

Thumbnail for 북한 APT 리퍼(Reaper)에서 만든 탈북민 사칭 한국해양수산연수원 타겟 인것으로 추측이 되는 악성코드-정보접근권.lnk(2024.11.1)

The sample is attributed in the excerpt to Reaper/APT37 and uses a Windows LNK file with a defector-themed lure connected to the Korea Institute of Maritime and Fisheries Technology. The LNK masquerades with a Microsoft Edge icon, extracts and opens an embedded PDF decoy, writes caption.dat and elephant.dat into the temporary directory, creates a batch file, and deletes the original shortcut to reduce visible traces. The execution chain starts hidden PowerShell, loads script content from elephant.dat, XOR-decrypts the payload in caption.dat with the key "d", allocates executable memory through kernel32 APIs, and runs the payload via CreateThread. The body provides hashes for the LNK and pCloud API URLs used for file access, making the sample useful for tracking APT37/RoKRAT-style shortcut-based delivery and in-memory execution tradecraft against South Korea-related targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 89c0d2cc1e71b17449eec454161d60da 2024-11-01 2025-02-19
URL https://api.pcloud.com/getfilel… 2024-11-04 2024-11-04
URL https://api.pcloud.com/listfold… 2024-11-04 2024-11-04
HASH 707e8cb56f32209ca837f2853801256… 2024-11-01 2024-11-04
HASH e9528f09f1e58ffc308893087f4a8b7… 2024-11-01 2024-11-04
DOMAIN telegram-df.org 2024-10-30 2024-11-04

Related Actors

Related Reports

« Back