APT37利用朝鲜政治话题针对韩国的攻击活动分析
2024-03-04 • 安恒信息 • Analysis of APT37's attack activities against South Korea using North Korean political topics •
DBAPPSecurity analyzed APT37 activity using North Korea related political themes to target South Korean users and researchers. The samples used compressed archives with Korean political lure documents, including commentary on anti state forces and other inter Korean affairs, while the core trojan changed little from earlier activity. The report says APT37 adjusted lure content and loading methods rather than rebuilding its malware, and increased archive size to reduce detection. The campaign fits APT37's long running focus on South Korean public and private sector targets and may benefit from heightened public attention to worsening North Korea and South Korea relations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 29f494e0a66158a808b39299267c5c53 | 2024-03-04 | 2024-03-04 |
| HASH | 5127bf820b33e4491a93165cfdd25be4 | 2024-03-04 | 2024-03-04 |