2024년 Webinar 안내장 사칭 APT 공격 포착

2024-01-16 Genians 2024 Webinar invitation impersonation APT attack detected

https://www.genians.co.kr/blog/webinar-apt

Thumbnail for 2024년 Webinar 안내장 사칭 APT 공격 포착

Genian observed an APT37-style spearphishing campaign that impersonated a real January 2024 unification strategy webinar on North Korea policy. The malicious email added a lookalike registration link that led victims to Dropbox, where a ZIP file delivered an LNK disguised as a PDF event notice. The LNK ran an oversized PowerShell command, extracted a decoy PDF, wrote public.dat and 241223.bat under the Public folder, and launched a staged payload flow that included an XOR-encrypted EXE masquerading as hybrid.zip. The report ties the tradecraft to prior APT37 patterns involving cloud storage abuse and attempted data exfiltration through pCloud.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2304183c6738e42ba89fc29f881b0684 2024-01-16 2024-01-16
HASH 4825fc554f9565ad356501293363c901 2024-01-16 2024-01-16
HASH 485af6ea63bbec8ae02f8a6184cae96f 2024-01-16 2024-01-16
HASH 300fb8e4294e902efe736e42ea262266 2024-01-16 2024-01-16
EMAIL [email protected] 2024-01-16 2024-01-16

Related Actors

Related Reports

« Back