2024년 Webinar 안내장 사칭 APT 공격 포착
2024-01-16 • Genians • 2024 Webinar invitation impersonation APT attack detected •
Genian observed an APT37-style spearphishing campaign that impersonated a real January 2024 unification strategy webinar on North Korea policy. The malicious email added a lookalike registration link that led victims to Dropbox, where a ZIP file delivered an LNK disguised as a PDF event notice. The LNK ran an oversized PowerShell command, extracted a decoy PDF, wrote public.dat and 241223.bat under the Public folder, and launched a staged payload flow that included an XOR-encrypted EXE masquerading as hybrid.zip. The report ties the tradecraft to prior APT37 patterns involving cloud storage abuse and attempted data exfiltration through pCloud.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2304183c6738e42ba89fc29f881b0684 | 2024-01-16 | 2024-01-16 |
| HASH | 4825fc554f9565ad356501293363c901 | 2024-01-16 | 2024-01-16 |
| HASH | 485af6ea63bbec8ae02f8a6184cae96f | 2024-01-16 | 2024-01-16 |
| HASH | 300fb8e4294e902efe736e42ea262266 | 2024-01-16 | 2024-01-16 |
| [email protected] | 2024-01-16 | 2024-01-16 |