탈북자 분들을 노리는 북한 해킹 단체 APT37(Reaper)에 만든 악성코드-김x민대표님모금캠페인.lnk(2024.10.31)

2025-06-27 Sakai Malware Created by North Korean Hacking Group APT37 (Reaper) Targeting North Korean Defectors - Kim X-min Representative Fundraising Campaign.lnk (2024.10.31)

https://wezard4u.tistory.com/429521

Thumbnail for 탈북자 분들을 노리는 북한 해킹 단체 APT37(Reaper)에 만든 악성코드-김x민대표님모금캠페인.lnk(2024.10.31)

APT37/Reaper is linked in the source to a malicious LNK file disguised as a fundraising campaign for a North Korean defector organization, using the health situation of a Free North Korea Radio representative as the lure. The LNK searches for a specific oversized shortcut file, extracts and opens a decoy PDF, writes an encoded EXE payload as caption.dat, creates elephant.dat and sharke.bat, and executes the batch chain through PowerShell. The extracted payload is XOR-decoded with the key d, loaded into memory with kernel32.dll P/Invoke calls such as GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject, and executed reflectively rather than simply dropped and run. The source provides hashes for the LNK sample and describes a victimology pattern focused on North Korean defectors, making it relevant for defenders tracking APT37 social-engineering lures and fileless-style execution chains.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c045b9da0456430268861da18735f7e… 2024-11-01 2025-06-27
HASH 144928fc87e1d50f5ed162bb1651ab24 2024-11-01 2025-06-27
HASH e917166ed0096688994709acb94233b… 2024-11-01 2025-06-27

Related Actors

Related Reports

« Back