작전명 아르테미스: HWP 기반 DLL 사이드 로딩 공격 분석
2025-12-21 • Genians • Operation Artemis: Analysis of HWP-Based DLL Side-Loading Attacks •
Genians identifies Operation Artemis as an APT37 campaign that used spear-phishing and malicious HWP/HWPX documents against South Korean targets interested in North Korea, human rights, abduction issues, broadcast interviews, seminars, and policy events. The infection chain begins when embedded HWP OLE objects disguised as hyperlinks create a malicious version.dll in the temporary directory and launch renamed Sysinternals VolumeId utilities such as Volumeid1.exe, vhelp.exe, or mhelp.exe for DLL side-loading. The side-loaded DLL hides payloads behind layered XOR decryption, activates x64 shellcode, and ultimately delivers RoKRAT, while the campaign also reuses APT37 tradecraft involving steganographic image payloads. Document metadata and repeated PDB paths, including Artemis-related fields and HwpOLE build paths, connect multiple samples into a consistent campaign observed from August through November. RoKRAT analysis identified Yandex Cloud tokens and account reuse tied to earlier APT37 cloud-service abuse, showing continued reliance on legitimate cloud platforms for C2 and payload operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d287dcaeaf17c9dae8a253994502ee58 | 2025-12-21 | 2025-12-21 |
| HASH | 7e8c24bb3b50d68227ff2b7193d548dd | 2025-12-21 | 2025-12-21 |
| HASH | 2f3dff7779795fc01291b0a31d723aca | 2025-12-21 | 2025-12-21 |
| HASH | c0cac70c93d213d113001e3410c24fd2 | 2025-12-21 | 2025-12-21 |
| HASH | f3603f68aadc8bc1ea8939132f0d5252 | 2025-12-21 | 2025-12-21 |
| HASH | ea95109b608841d2f99a25bd2646ff43 | 2025-12-21 | 2025-12-21 |
| HASH | d2b2c6646535a62e4c005613d6a036f0 | 2025-12-21 | 2025-12-21 |
| HASH | e726b59f96ab8360f323469d72b8b617 | 2025-12-21 | 2025-12-21 |
| HASH | 31662a24560b3fe1f34f0733e65509ff | 2025-12-21 | 2025-12-21 |
| HASH | 17171c644307b17d231ad404e25f08b1 | 2025-12-21 | 2025-12-21 |
| HASH | f13a4834e3e1613857b84a1203e2e182 | 2025-12-21 | 2025-12-21 |
| HASH | ad3433f5f64abdec7868a52341f14196 | 2025-12-21 | 2025-12-21 |
| HASH | a196fb11a423076f66f5e4b2d02813a9 | 2025-12-21 | 2025-12-21 |
| HASH | 8e4a99315a3ef443928ef25d90f84a09 | 2025-12-21 | 2025-12-21 |
| [email protected] | 2024-04-23 | 2025-12-21 |