APT37 그룹의 RoKRAT 파일리스 공격 증가

2024-03-27 Genians Cyber threat report on APT37, RokRAT, LNK

https://www.genians.co.kr/blog/threat_intelligence/rokrat

Thumbnail for APT37 그룹의 RoKRAT 파일리스 공격 증가

Genians reporting identifies an APT37 campaign observed after the Lunar New Year holiday, alongside Korea-focused state-backed groups such as Lazarus, Kimsuky, and Konni. The activity targets North Korea human-rights groups, journalists covering North Korea, defectors, and other North Korea-related personnel through spear-phishing. LNK files with embedded PowerShell commands are used for initial execution, including lures that combine a normal North Korea-themed PDF with a disguised shortcut file. The RoKRAT malware collects documents and recordings from victim systems and exfiltrates data through pCloud API-based C2 infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2024-03-27 2025-05-12
EMAIL [email protected] 2024-03-27 2025-05-12
EMAIL [email protected] 2024-03-27 2025-05-12
HASH 7bce02dc0026e271615d4d0e441ca397 2024-03-27 2024-04-03
HASH bdf18a2d9a94c348cac9efc51d59a75a 2024-03-27 2024-03-27
HASH 491947a5c5b97355989f674114e59a31 2024-03-27 2024-03-27
HASH 0ee76a97449a20eed335b4db7327cb44 2024-03-27 2024-03-27
HASH aff44804011d77e1050b912b6e6a62c5 2024-03-27 2024-03-27
HASH ad2761910997c801b3347bd3745dd2b9 2024-03-27 2024-03-27
HASH 81a7d6f88c0fb1705a16fc59ad261f35 2024-03-27 2024-03-27
URL https://dl.dropboxusercontent.c… 2024-03-27 2024-03-27
HASH fe5520783f715549cc3c4df9deaf89bf 2023-07-11 2024-03-27

Related Actors

Related Reports

« Back