우리 북한 해킹 단체 Reaper(리퍼)에서 만든 악성코드-인문사회분야 박사과정생 연구장려금지원 신청자격 요건 확인서.hwp(2024.5.24)
2024-06-06 • Sakai • Malware Created by the North Korean Hacking Group Reaper - Eligibility Confirmation Form for Research Grant Support for Doctoral Students in Humanities and Social Sciences.hwp (2024.5.24) •
APT37/Reaper activity is tied to a malicious HWP document disguised as an eligibility form for humanities and social-sciences doctoral research support. The excerpt says the group is associated with espionage-focused targeting of government, military, large-enterprise, human-rights, and regional business victims, and it links the tradecraft to RokRAT-style capabilities such as credential theft, data exfiltration, screenshots, system discovery, command execution, and file management. The document abuse centers on an embedded OLE object rather than an HWP software vulnerability, with compressed data revealing a hidden C2 URL under host.sharingdocument[.]one. The lure appears to impersonate a university research office context, making the sample relevant for defenders tracking DPRK document-based social engineering and cloud/C2-enabled collection activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1b57075fb924a5c7a1e823e03d08bfc… | 2024-06-06 | 2024-06-06 |
| HASH | 2222f1d7ccd05655f0492769bc54ec0… | 2024-06-06 | 2024-06-06 |
| HASH | 9bd2de45e688a5a9561dc622e1336e37 | 2024-06-06 | 2024-06-06 |