APT37 공격 그룹의 지속적 위협 공격

2025-03-20 Hauri ( Document No : DT-20250320-001 )

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=74

Attachments

2025-03-20ììëìë³ê³ìAPT37ê³µê²êë¹ìììììíê³µê².pdf (1 MB)

APT37 activity is described using malicious LNK files disguised as Microsoft Store update content to trigger infection. When executed, the LNK drops a decoy document and batch file, changes the shortcut into an HTML file, and uses obfuscated code to retrieve a CAB payload from a compromised legitimate South Korean company website. The infection chain registers MicrosoftAppStoreAutoUpdateTaskMachine as a scheduled task, runs MicrosoftAppStore.exe with appstore.version, and attempts to download an additional MicroAppStoreTemp28h2.bat payload from the same abused infrastructure. The decoy themes include aviation, banking, and security, showing socially targeted lures across sensitive sectors, with hashes and C2 paths supplied for detection and response.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 90026c2dbdb294b13fd03da2be011dd1 2025-03-20 2025-09-14
HASH dea8785b4c54d9ae6fa9c24de77531eb 2025-03-20 2025-03-20
HASH de26582dda75c138f35e932dd2424eea 2025-03-20 2025-03-20
HASH 345decffc710344a55fe121df7692df8 2025-03-20 2025-03-20
HASH f51f60834ba1734ae3765661d0f2654a 2025-03-20 2025-03-20
HASH bdde4878f82dda79d983464153d71009 2025-03-20 2025-03-20
HASH 640c6f987b24f35bb29d3db0f4b8c87b 2025-03-20 2025-03-20
HASH 8a0d6260ecdf551342633c93c03e4511 2025-03-20 2025-03-20

Related Actors

Related Reports

« Back