Internet Explorer 0-day exploited by North Korean actor APT37

2022-12-07 Google

https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37

Thumbnail for Internet Explorer 0-day exploited by North Korean actor APT37

Google TAG reported that North Korean government-backed APT37 exploited CVE-2022-41128, an Internet Explorer JScript zero-day, through malicious Office documents targeting users in South Korea. The campaign used an Itaewon tragedy-themed document that fetched a remote RTF template and attacker-controlled HTML, allowing Office to render the exploit through IE even when IE was not the default browser. TAG observed server-side cookie checks, shellcode that cleared IE cache and history, and a follow-on download stage, and it linked similar documents to the same activity. Representative indicators included hashes for the exploit documents and infrastructure such as word-template.net, openxmlformat.org, ms-office.services, and template-openxml.com.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c49b4d370ad0dcd1e28ee8f525ac8e3… 2022-12-07 2025-02-10
HASH 08f93351d0d3905bee5b0c2b9215d44… 2022-12-07 2022-12-07
HASH af5fb99d3ff18bc625fb63f792ed7cd… 2022-12-07 2022-12-07
HASH 926a947ea2b59d3e9a5a6875b4de2bd… 2022-12-07 2022-12-07
HASH 56ca24b57c4559f834c190d50b0fe89… 2022-12-07 2022-12-07
HASH 3bff571823421c013e79cc10793f238… 2022-12-07 2022-12-07
DOMAIN template-openxml.com 2022-12-07 2022-12-07
DOMAIN word-template.net 2022-11-17 2022-12-07
DOMAIN ms-offices.com 2022-11-17 2022-12-07

Related Actors

Related Reports

« Back