APT37의 프리텍스팅 기반 표적 침투: 페이스북 정찰과 소프트웨어 변조 공격 분석
2026-04-12 • Genians • Analysis of APT37's Pretexting-Based Targeted Intrusion: Facebook Reconnaissance and Software Tampering Attack •
https://www.genians.co.kr/blog/threat_intelligence/pretexting
APT37 used Facebook accounts presenting locations in Pyongyang and Pyongsong to identify targets, build trust through friend requests and Messenger conversations, and move victims toward Telegram delivery. The lure claimed encrypted military-weapons PDF documents required a dedicated viewer, leading targets to run a tampered Wondershare PDFelement installer named to resemble a security-related PDF viewer. The modified installer changed its entry point to execute shellcode from a code cave, then created a suspended dism.exe process, decrypted payload code, and injected it into remote process memory. The activity also abused the Seoul branch site of a Japanese real-estate information service as C2 infrastructure and used a JPG-disguised payload, showing an evasion-focused chain combining social engineering, PE patching, process injection, and legitimate infrastructure abuse.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 28d0143718153bf04c1919a26bb70c2d | 2026-04-12 | 2026-04-12 |
| HASH | c681fe3f42e82e9240afe97c23971cbc | 2026-04-12 | 2026-04-12 |
| HASH | 36be2cbb59cd1c3f745d5f80f9aee21c | 2026-04-12 | 2026-04-12 |
| HASH | d44a22d2c969988a65c7d927e22364c8 | 2026-04-12 | 2026-04-12 |
| HASH | c637b3e7d74c2d678663454d16311b15 | 2026-04-12 | 2026-04-12 |
| HASH | 085128b4e96633c82beb2101f5c525e4 | 2026-04-12 | 2026-04-12 |
| [email protected] | 2026-04-12 | 2026-04-12 | |
| URL | http://japanroom.com/board/DATA… | 2026-04-12 | 2026-04-12 |
| DOMAIN | japanroom.com | 2026-04-12 | 2026-04-12 |
| [email protected] | 2025-08-03 | 2026-04-12 | |
| IPv4 | 38.32.68.195 | 2025-02-25 | 2026-04-12 |
| IPv4 | 222.122.49.15 | 2021-04-19 | 2026-04-12 |