APT37 그룹의 RoKRAT 파일리스 공격 증가
2024-03-27 • Genians • Cyber threat report on APT37, RokRAT, LNK •
Genians reporting identifies an APT37 campaign observed after the Lunar New Year holiday, alongside Korea-focused state-backed groups such as Lazarus, Kimsuky, and Konni. The activity targets North Korea human-rights groups, journalists covering North Korea, defectors, and other North Korea-related personnel through spear-phishing. LNK files with embedded PowerShell commands are used for initial execution, including lures that combine a normal North Korea-themed PDF with a disguised shortcut file. The RoKRAT malware collects documents and recordings from victim systems and exfiltrates data through pCloud API-based C2 infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2024-03-27 | 2025-05-12 | |
| [email protected] | 2024-03-27 | 2025-05-12 | |
| [email protected] | 2024-03-27 | 2025-05-12 | |
| HASH | 7bce02dc0026e271615d4d0e441ca397 | 2024-03-27 | 2024-04-03 |
| HASH | bdf18a2d9a94c348cac9efc51d59a75a | 2024-03-27 | 2024-03-27 |
| HASH | 491947a5c5b97355989f674114e59a31 | 2024-03-27 | 2024-03-27 |
| HASH | 0ee76a97449a20eed335b4db7327cb44 | 2024-03-27 | 2024-03-27 |
| HASH | aff44804011d77e1050b912b6e6a62c5 | 2024-03-27 | 2024-03-27 |
| HASH | ad2761910997c801b3347bd3745dd2b9 | 2024-03-27 | 2024-03-27 |
| HASH | 81a7d6f88c0fb1705a16fc59ad261f35 | 2024-03-27 | 2024-03-27 |
| URL | https://dl.dropboxusercontent.c… | 2024-03-27 | 2024-03-27 |
| HASH | fe5520783f715549cc3c4df9deaf89bf | 2023-07-11 | 2024-03-27 |