APT37利用朝鲜政治话题针对韩国的攻击活动分析

2024-03-04 安恒信息 Analysis of APT37's attack activities against South Korea using North Korean political topics

https://app-martech.dbappsecurity.com.cn/resources/ResourcePc/ResourcePcInfo?pf_uid=17709_1776&id=321&source=1&pf_type=3&channel_id=8987&channel_name=%E5%AE%89%E6%81%92%E7%A0%94%E7%A9%B6%E9%99%A2&tag_id=2824468d92446b27

Thumbnail for APT37利用朝鲜政治话题针对韩国的攻击活动分析

DBAPPSecurity analyzed APT37 activity using North Korea related political themes to target South Korean users and researchers. The samples used compressed archives with Korean political lure documents, including commentary on anti state forces and other inter Korean affairs, while the core trojan changed little from earlier activity. The report says APT37 adjusted lure content and loading methods rather than rebuilding its malware, and increased archive size to reduce detection. The campaign fits APT37's long running focus on South Korean public and private sector targets and may benefit from heightened public attention to worsening North Korea and South Korea relations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 29f494e0a66158a808b39299267c5c53 2024-03-04 2024-03-04
HASH 5127bf820b33e4491a93165cfdd25be4 2024-03-04 2024-03-04

Related Actors

Related Reports

« Back