APT37 复盘分析报告(part2):木马与工具

2020-03-25 NSFOCUS APT37 review analysis report (part2): Trojans and tools

http://blog.nsfocus.net/apt37-part2-0325/

Thumbnail for APT37 复盘分析报告(part2):木马与工具

NSFOCUS profiles APT37, also known as Group123, Venus 121 and Reaper, as a North Korea-linked actor active since 2012 and focused on neighboring countries, especially South Korea. The tool review highlights PoorWeb, RokRat, NavRat, KevDroid and PubNub, describing how APT37 uses HWP-delivered malware, public cloud services such as Dropbox and pCloud, Naver mail, FTP and PubNub-style messaging for command execution, file theft, credential collection and payload staging. The excerpt emphasizes RokRat’s cloud-based C2 and screenshot/document-stealing functions, NavRat’s Naver mail control channel, and PoorWeb behavior from Operation Imitation Game, giving defenders concrete malware families and communication patterns to track.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
URL https://api.dropboxapi.com/2/fi… 2018-09-21 2025-08-29
URL https://api.pcloud.com/getfilel… 2020-03-25 2020-03-25
URL https://api.pcloud.com/uploadfi… 2020-03-25 2020-03-25
URL https://api.pcloud.com/deletefi… 2020-03-25 2020-03-25
DOMAIN ps.pndsn.com 2018-04-02 2020-03-25

Related Actors

Related Reports

« Back