한국 국가안보전략 싱크탱크 위장 APT37 공격 사례 분석 (작전명. 토이박스 스토리)

2025-05-12 Genians Cyber threat report on APT37, RokRAT, LNK

https://www.genians.co.kr/blog/threat_intelligence/toybox-story

Thumbnail for 한국 국가안보전략 싱크탱크 위장 APT37 공격 사례 분석 (작전명. 토이박스 스토리)

Genians identified Operation ToyBox Story as a March 2025 APT37 spear-phishing campaign against activists and experts working on North Korea issues. The lures impersonated a North Korea-focused expert and a South Korean national security think tank event, directing recipients to Dropbox-hosted ZIP files containing malicious LNK shortcuts. When opened, the LNK files executed hidden PowerShell commands, staged BAT and DAT files under the temporary directory, transformed shellcode with XOR logic, and loaded RoKRAT in memory. The RoKRAT payload gathered system information, screenshots, process and removable-drive data, supported command execution and cleanup routines, and communicated through cloud-service C2 infrastructure, including Dropbox and API patterns for pCloud and Yandex. The report links the activity to APT37’s repeated use of cloud services, fileless techniques, and RoKRAT variants with limited code changes to reduce antivirus detection.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 37.120.210.2 2025-05-12 2026-01-21
EMAIL [email protected] 2024-04-23 2025-12-21
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
URL https://cloud-api.yandex.net/v1… 2025-03-10 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/uploadfi… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/getfilel… 2024-04-03 2025-08-29
URL https://api.pcloud.com/listfold… 2024-04-03 2025-08-29
URL https://api.dropboxapi.com/2/fi… 2023-01-16 2025-08-29
URL https://api.dropboxapi.com/2/fi… 2018-09-21 2025-08-29
URL https://api.pcloud.com/deletefi… 2018-09-21 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29
HASH 7cc8ce5374ff9eacd38491b75cbedf89 2025-05-12 2025-05-12
HASH d5d48f044ff16ef6a4d5bde060ed5cee 2025-05-12 2025-05-12
HASH 8f339a09f0d0202cfaffbd38469490ec 2025-05-12 2025-05-12
HASH 324688238c42d7190a2b50303cbc6a3c 2025-05-12 2025-05-12
HASH 81c08366ea7fc0f933f368b120104384 2025-05-12 2025-05-12
EMAIL [email protected] 2025-05-12 2025-05-12
EMAIL [email protected] 2025-05-12 2025-05-12
EMAIL [email protected] 2025-05-12 2025-05-12
EMAIL [email protected] 2025-05-12 2025-05-12
EMAIL [email protected] 2025-05-12 2025-05-12
EMAIL [email protected] 2025-05-12 2025-05-12
IPv4 89.147.101.65 2025-05-12 2025-05-12
IPv4 89.147.101.71 2025-05-12 2025-05-12
HASH 723f80d1843315717bc56e9e58e89be5 2025-03-27 2025-05-12
HASH 46ca088d5c052738d42bbd6231cc0ed5 2025-03-27 2025-05-12
HASH 2f431c4e65af9908d2182c6a093bf262 2025-03-27 2025-05-12
EMAIL [email protected] 2024-04-23 2025-05-12
EMAIL [email protected] 2024-03-27 2025-05-12
EMAIL [email protected] 2024-03-27 2025-05-12
EMAIL [email protected] 2024-03-27 2025-05-12
HASH 7822e53536c1cf86c3e44e31e77bd088 2023-09-19 2025-05-12
HASH d77c8449f1efc4bfb9ebff496442bbbc 2023-09-19 2025-05-12
HASH a635bd019674b25038cd8f02e15eebd2 2023-09-19 2025-05-12
HASH beeaca6a34fb05e73a6d8b7d2b8c2ee3 2023-09-19 2025-05-12

Related Actors

Related Reports

« Back