APT37 复盘分析报告(part2):木马与工具
2020-03-25 • NSFOCUS • APT37 review analysis report (part2): Trojans and tools •
NSFOCUS profiles APT37, also known as Group123, Venus 121 and Reaper, as a North Korea-linked actor active since 2012 and focused on neighboring countries, especially South Korea. The tool review highlights PoorWeb, RokRat, NavRat, KevDroid and PubNub, describing how APT37 uses HWP-delivered malware, public cloud services such as Dropbox and pCloud, Naver mail, FTP and PubNub-style messaging for command execution, file theft, credential collection and payload staging. The excerpt emphasizes RokRat’s cloud-based C2 and screenshot/document-stealing functions, NavRat’s Naver mail control channel, and PoorWeb behavior from Operation Imitation Game, giving defenders concrete malware families and communication patterns to track.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://content.dropboxapi.com/… | 2020-03-25 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2018-09-21 | 2025-09-03 |
| URL | https://api.dropboxapi.com/2/fi… | 2018-09-21 | 2025-08-29 |
| URL | https://api.pcloud.com/getfilel… | 2020-03-25 | 2020-03-25 |
| URL | https://api.pcloud.com/uploadfi… | 2020-03-25 | 2020-03-25 |
| URL | https://api.pcloud.com/deletefi… | 2020-03-25 | 2020-03-25 |
| DOMAIN | ps.pndsn.com | 2018-04-02 | 2020-03-25 |