AI 딥페이크 사칭 캠페인 후속 Python 백도어 위협 분석

2026-05-10 Genians Follow-up Threat Analysis of a Python Backdoor in an AI Deepfake Impersonation Campaign

https://www.genians.co.kr/blog/threat_intelligence/python

Thumbnail for AI 딥페이크 사칭 캠페인 후속 Python 백도어 위협 분석

Genians links this campaign to suspected APT37 activity, describing spearphishing emails that deliver ZIP archives containing malicious LNK files. The lures include airline e-tickets, North Korea research event invitations, and impersonation of defense or police officials to induce execution. When opened, the LNK reconstructs obfuscated commands through environment-variable substitution, launches chained BAT scripts, and maintains C2 communication to fetch additional payloads. The final payload is a compiled Python bytecode backdoor disguised with a .cat extension, enabling remote command execution and follow-on actions such as persistence, file collection, and system information theft. The report notes continuity with earlier APT37-linked cases through similar social engineering, script obfuscation, multistage downloads, and overlapping Cafe24 and French-hosted infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 211.239.157.126 2026-06-14 2026-06-14
DOMAIN fe01.co.kr 2026-06-14 2026-06-14
IPv4 218.150.78.198 2026-06-14 2026-06-14
DOMAIN choisy.fr 2026-05-10 2026-05-10
IPv4 220.73.160.23 2026-05-10 2026-05-10
DOMAIN printory.kr 2026-05-10 2026-05-10
DOMAIN ycpatent.co.kr 2026-05-10 2026-05-10
DOMAIN kmot.co.kr 2026-05-10 2026-05-10
IPv4 183.111.174.69 2026-05-10 2026-05-10
DOMAIN oxenhan1.cafe24.com 2026-05-10 2026-05-10
HASH 7922f91281e8b0fe00518d05bf295b4a 2026-05-10 2026-05-10
HASH 16d7be5ebc3c2ff1cffbb83b965fd4fb 2026-05-10 2026-05-10
HASH 1aa7751332710f4e963a708243d3d550 2026-05-10 2026-05-10
HASH f7b2e0cebd7793c8cfee2c7c5b93df9c 2026-05-10 2026-05-10
HASH b5f9cd67cb32f44c138c382e17b06fd6 2026-05-10 2026-05-10
HASH abbb362cdfe14b56b3a13a2a55937ee4 2026-05-10 2026-05-10
HASH 255155bad9af5e2c6cf550ff2a95219d 2026-05-10 2026-05-10
HASH 33c97fc4eacd73addbae9e6cde54a77d 2025-09-14 2025-09-14
HASH fcb97f87905a33af565b0a4f4e884d61 2025-09-14 2025-09-14
HASH 09dabe5ab566e50ab4526504345af297 2025-09-14 2025-09-14
IPv4 51.158.21.1 2025-09-14 2025-09-14
HASH 804d12b116bb40282fbf245db885c093 2022-08-29 2022-08-29

Related Actors

Related Reports

« Back