한글 문서로 위장한 두 공격 그룹의 악성코드 비교

2025-03-04 Logpresso Comparison of Malware From Two Attack Groups Disguised as Hangul Documents

https://logpresso.com/ko/blog/2025-03-04-comparison-of-malware-disguised-as-a-hangul-document

Thumbnail for 한글 문서로 위장한 두 공격 그룹의 악성코드 비교

Logpresso compares two Korean-language document lure cases and separates them into APT37 and Konni activity based on file structure, execution flow, metadata, C2 behavior, and decryption keys. The APT37 case used a Hangul document titled around North Korean influence themes, abused an embedded OLE object, dropped batch and PowerShell components, decrypted shellcode in memory, and ultimately ran RokRAT against likely South Korean defense-sector personnel and North Korea researchers. RokRAT collected SMBIOS details, periodic desktop screenshots, and document or recording file information, then used cloud-service style C2 paths including Yandex with possible Dropbox and pCloud support. The Konni case used an LNK file disguised as a Hangul document about virtual-asset business inspection plans, launched PowerShell, VBScript, and batch files, established persistence, collected file listings and system information, and communicated with forum.flasholr-app.com using RC4-encrypted parameters.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 81051bcc2cf1bedf378224b0a93e2877 2025-03-04 2026-01-14
HASH 4a89126a7e3190866b3eebeb8b8ee9b7 2025-03-04 2026-01-14
HASH 3eac72d8dfab856788becf2cafc65328 2025-03-04 2026-01-14
HASH 34ca15b188ccfc83c54658f06acc548b 2025-03-04 2026-01-14
HASH a7557684eb1ab6044fccf69b442a559f 2025-03-04 2026-01-14
HASH b927851f70d91fd4a1398161fd0a7b78 2025-03-04 2026-01-14
HASH f789c4e68c549d97fe40179b1777a39b 2025-03-04 2026-01-14
HASH 8b3f90264310fb44b2fb584392a53b8d 2025-03-04 2026-01-14
HASH a68acc516eca9b2be1b89addd4f3f723 2025-03-04 2026-01-14
HASH 12ac9f346e9ac80c7596bccbf8cd9f9c 2025-03-04 2026-01-14
HASH 835a74b3c33a66678c66118dbe26dccf 2025-03-04 2026-01-14
HASH 82d85f391c8a1aaa0a2b9500993156c5 2025-03-04 2026-01-14
HASH 5b819ad2bcd8ad68af558e970d1d325e 2025-03-04 2026-01-14
HASH fa79b143af6bfc64e52e667cd8a2eb66 2025-03-04 2026-01-14
HASH 18db9e11bd0829642df9f6774339fc85 2025-03-04 2026-01-14
HASH 1b6eb87d8d52f699c89c2f6e7451bf28 2025-03-04 2026-01-14
URL http://forum.flasholr-app.com/w… 2025-03-04 2026-01-14
URL https://teamfuels.com/modules/i… 2025-02-20 2026-01-14
URL http://forum.flasholr-app.com/w… 2025-02-20 2026-01-14
DOMAIN teamfuels.com 2025-02-20 2026-01-14
DOMAIN forum.flasholr-app.com 2025-02-20 2026-01-14
HASH e37c8f6aba686aab3d7ecedbd1d0ef43 2025-02-14 2026-01-14
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/uploadfi… 2024-04-03 2025-08-29
URL https://api.pcloud.com/getfilel… 2024-04-03 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29
URL http://forum.flasholr-app.com/w… 2025-03-04 2025-03-04

Related Actors

Related Reports

« Back