작전명 아르테미스: HWP 기반 DLL 사이드 로딩 공격 분석

2025-12-21 Genians Operation Artemis: Analysis of HWP-Based DLL Side-Loading Attacks

https://www.genians.co.kr/blog/threat_intelligence/dll

Thumbnail for 작전명 아르테미스: HWP 기반 DLL 사이드 로딩 공격 분석

Genians identifies Operation Artemis as an APT37 campaign that used spear-phishing and malicious HWP/HWPX documents against South Korean targets interested in North Korea, human rights, abduction issues, broadcast interviews, seminars, and policy events. The infection chain begins when embedded HWP OLE objects disguised as hyperlinks create a malicious version.dll in the temporary directory and launch renamed Sysinternals VolumeId utilities such as Volumeid1.exe, vhelp.exe, or mhelp.exe for DLL side-loading. The side-loaded DLL hides payloads behind layered XOR decryption, activates x64 shellcode, and ultimately delivers RoKRAT, while the campaign also reuses APT37 tradecraft involving steganographic image payloads. Document metadata and repeated PDB paths, including Artemis-related fields and HwpOLE build paths, connect multiple samples into a consistent campaign observed from August through November. RoKRAT analysis identified Yandex Cloud tokens and account reuse tied to earlier APT37 cloud-service abuse, showing continued reliance on legitimate cloud platforms for C2 and payload operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d287dcaeaf17c9dae8a253994502ee58 2025-12-21 2025-12-21
HASH 7e8c24bb3b50d68227ff2b7193d548dd 2025-12-21 2025-12-21
HASH 2f3dff7779795fc01291b0a31d723aca 2025-12-21 2025-12-21
HASH c0cac70c93d213d113001e3410c24fd2 2025-12-21 2025-12-21
HASH f3603f68aadc8bc1ea8939132f0d5252 2025-12-21 2025-12-21
HASH ea95109b608841d2f99a25bd2646ff43 2025-12-21 2025-12-21
HASH d2b2c6646535a62e4c005613d6a036f0 2025-12-21 2025-12-21
HASH e726b59f96ab8360f323469d72b8b617 2025-12-21 2025-12-21
HASH 31662a24560b3fe1f34f0733e65509ff 2025-12-21 2025-12-21
HASH 17171c644307b17d231ad404e25f08b1 2025-12-21 2025-12-21
HASH f13a4834e3e1613857b84a1203e2e182 2025-12-21 2025-12-21
HASH ad3433f5f64abdec7868a52341f14196 2025-12-21 2025-12-21
HASH a196fb11a423076f66f5e4b2d02813a9 2025-12-21 2025-12-21
HASH 8e4a99315a3ef443928ef25d90f84a09 2025-12-21 2025-12-21
EMAIL [email protected] 2024-04-23 2025-12-21

Related Actors

Related Reports

« Back