한국 국가안보전략 싱크탱크 위장 APT37 공격 사례 분석 (작전명. 토이박스 스토리)
2025-05-12 • Genians • Cyber threat report on APT37, RokRAT, LNK •
https://www.genians.co.kr/blog/threat_intelligence/toybox-story
Genians identified Operation ToyBox Story as a March 2025 APT37 spear-phishing campaign against activists and experts working on North Korea issues. The lures impersonated a North Korea-focused expert and a South Korean national security think tank event, directing recipients to Dropbox-hosted ZIP files containing malicious LNK shortcuts. When opened, the LNK files executed hidden PowerShell commands, staged BAT and DAT files under the temporary directory, transformed shellcode with XOR logic, and loaded RoKRAT in memory. The RoKRAT payload gathered system information, screenshots, process and removable-drive data, supported command execution and cleanup routines, and communicated through cloud-service C2 infrastructure, including Dropbox and API patterns for pCloud and Yandex. The report links the activity to APT37’s repeated use of cloud services, fileless techniques, and RoKRAT variants with limited code changes to reduce antivirus detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 37.120.210.2 | 2025-05-12 | 2026-01-21 |
| [email protected] | 2024-04-23 | 2025-12-21 | |
| URL | https://content.dropboxapi.com/… | 2020-03-25 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2018-09-21 | 2025-09-03 |
| URL | https://cloud-api.yandex.net/v1… | 2025-03-10 | 2025-08-29 |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2025-08-29 |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2025-08-29 |
| URL | https://api.pcloud.com/uploadfi… | 2024-04-03 | 2025-08-29 |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2025-08-29 |
| URL | https://api.pcloud.com/getfilel… | 2024-04-03 | 2025-08-29 |
| URL | https://api.pcloud.com/listfold… | 2024-04-03 | 2025-08-29 |
| URL | https://api.dropboxapi.com/2/fi… | 2023-01-16 | 2025-08-29 |
| URL | https://api.dropboxapi.com/2/fi… | 2018-09-21 | 2025-08-29 |
| URL | https://api.pcloud.com/deletefi… | 2018-09-21 | 2025-08-29 |
| DOMAIN | cloud-api.yandex.net | 2018-02-27 | 2025-08-29 |
| HASH | 7cc8ce5374ff9eacd38491b75cbedf89 | 2025-05-12 | 2025-05-12 |
| HASH | d5d48f044ff16ef6a4d5bde060ed5cee | 2025-05-12 | 2025-05-12 |
| HASH | 8f339a09f0d0202cfaffbd38469490ec | 2025-05-12 | 2025-05-12 |
| HASH | 324688238c42d7190a2b50303cbc6a3c | 2025-05-12 | 2025-05-12 |
| HASH | 81c08366ea7fc0f933f368b120104384 | 2025-05-12 | 2025-05-12 |
| [email protected] | 2025-05-12 | 2025-05-12 | |
| [email protected] | 2025-05-12 | 2025-05-12 | |
| [email protected] | 2025-05-12 | 2025-05-12 | |
| [email protected] | 2025-05-12 | 2025-05-12 | |
| [email protected] | 2025-05-12 | 2025-05-12 | |
| [email protected] | 2025-05-12 | 2025-05-12 | |
| IPv4 | 89.147.101.65 | 2025-05-12 | 2025-05-12 |
| IPv4 | 89.147.101.71 | 2025-05-12 | 2025-05-12 |
| HASH | 723f80d1843315717bc56e9e58e89be5 | 2025-03-27 | 2025-05-12 |
| HASH | 46ca088d5c052738d42bbd6231cc0ed5 | 2025-03-27 | 2025-05-12 |
| HASH | 2f431c4e65af9908d2182c6a093bf262 | 2025-03-27 | 2025-05-12 |
| [email protected] | 2024-04-23 | 2025-05-12 | |
| [email protected] | 2024-03-27 | 2025-05-12 | |
| [email protected] | 2024-03-27 | 2025-05-12 | |
| [email protected] | 2024-03-27 | 2025-05-12 | |
| HASH | 7822e53536c1cf86c3e44e31e77bd088 | 2023-09-19 | 2025-05-12 |
| HASH | d77c8449f1efc4bfb9ebff496442bbbc | 2023-09-19 | 2025-05-12 |
| HASH | a635bd019674b25038cd8f02e15eebd2 | 2023-09-19 | 2025-05-12 |
| HASH | beeaca6a34fb05e73a6d8b7d2b8c2ee3 | 2023-09-19 | 2025-05-12 |