탈북자 분들을 노리는 북한 해킹 단체 APT37(Reaper)에 만든 악성코드-김x민대표님모금캠페인.lnk(2024.10.31)
2025-06-27 • Sakai • Malware Created by North Korean Hacking Group APT37 (Reaper) Targeting North Korean Defectors - Kim X-min Representative Fundraising Campaign.lnk (2024.10.31) •
APT37/Reaper is linked in the source to a malicious LNK file disguised as a fundraising campaign for a North Korean defector organization, using the health situation of a Free North Korea Radio representative as the lure. The LNK searches for a specific oversized shortcut file, extracts and opens a decoy PDF, writes an encoded EXE payload as caption.dat, creates elephant.dat and sharke.bat, and executes the batch chain through PowerShell. The extracted payload is XOR-decoded with the key d, loaded into memory with kernel32.dll P/Invoke calls such as GlobalAlloc, VirtualProtect, CreateThread, and WaitForSingleObject, and executed reflectively rather than simply dropped and run. The source provides hashes for the LNK sample and describes a victimology pattern focused on North Korean defectors, making it relevant for defenders tracking APT37 social-engineering lures and fileless-style execution chains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c045b9da0456430268861da18735f7e… | 2024-11-01 | 2025-06-27 |
| HASH | 144928fc87e1d50f5ed162bb1651ab24 | 2024-11-01 | 2025-06-27 |
| HASH | e917166ed0096688994709acb94233b… | 2024-11-01 | 2025-06-27 |