AI 딥페이크 사칭 캠페인 후속 Python 백도어 위협 분석
2026-05-10 • Genians • Follow-up Threat Analysis of a Python Backdoor in an AI Deepfake Impersonation Campaign •
Genians links this campaign to suspected APT37 activity, describing spearphishing emails that deliver ZIP archives containing malicious LNK files. The lures include airline e-tickets, North Korea research event invitations, and impersonation of defense or police officials to induce execution. When opened, the LNK reconstructs obfuscated commands through environment-variable substitution, launches chained BAT scripts, and maintains C2 communication to fetch additional payloads. The final payload is a compiled Python bytecode backdoor disguised with a .cat extension, enabling remote command execution and follow-on actions such as persistence, file collection, and system information theft. The report notes continuity with earlier APT37-linked cases through similar social engineering, script obfuscation, multistage downloads, and overlapping Cafe24 and French-hosted infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 211.239.157.126 | 2026-06-14 | 2026-06-14 |
| DOMAIN | fe01.co.kr | 2026-06-14 | 2026-06-14 |
| IPv4 | 218.150.78.198 | 2026-06-14 | 2026-06-14 |
| DOMAIN | choisy.fr | 2026-05-10 | 2026-05-10 |
| IPv4 | 220.73.160.23 | 2026-05-10 | 2026-05-10 |
| DOMAIN | printory.kr | 2026-05-10 | 2026-05-10 |
| DOMAIN | ycpatent.co.kr | 2026-05-10 | 2026-05-10 |
| DOMAIN | kmot.co.kr | 2026-05-10 | 2026-05-10 |
| IPv4 | 183.111.174.69 | 2026-05-10 | 2026-05-10 |
| DOMAIN | oxenhan1.cafe24.com | 2026-05-10 | 2026-05-10 |
| HASH | 7922f91281e8b0fe00518d05bf295b4a | 2026-05-10 | 2026-05-10 |
| HASH | 16d7be5ebc3c2ff1cffbb83b965fd4fb | 2026-05-10 | 2026-05-10 |
| HASH | 1aa7751332710f4e963a708243d3d550 | 2026-05-10 | 2026-05-10 |
| HASH | f7b2e0cebd7793c8cfee2c7c5b93df9c | 2026-05-10 | 2026-05-10 |
| HASH | b5f9cd67cb32f44c138c382e17b06fd6 | 2026-05-10 | 2026-05-10 |
| HASH | abbb362cdfe14b56b3a13a2a55937ee4 | 2026-05-10 | 2026-05-10 |
| HASH | 255155bad9af5e2c6cf550ff2a95219d | 2026-05-10 | 2026-05-10 |
| HASH | 33c97fc4eacd73addbae9e6cde54a77d | 2025-09-14 | 2025-09-14 |
| HASH | fcb97f87905a33af565b0a4f4e884d61 | 2025-09-14 | 2025-09-14 |
| HASH | 09dabe5ab566e50ab4526504345af297 | 2025-09-14 | 2025-09-14 |
| IPv4 | 51.158.21.1 | 2025-09-14 | 2025-09-14 |
| HASH | 804d12b116bb40282fbf245db885c093 | 2022-08-29 | 2022-08-29 |