Internet Explorer 0-day exploited by North Korean actor APT37
2022-12-07 • Google •
Google TAG reported that North Korean government-backed APT37 exploited CVE-2022-41128, an Internet Explorer JScript zero-day, through malicious Office documents targeting users in South Korea. The campaign used an Itaewon tragedy-themed document that fetched a remote RTF template and attacker-controlled HTML, allowing Office to render the exploit through IE even when IE was not the default browser. TAG observed server-side cookie checks, shellcode that cleared IE cache and history, and a follow-on download stage, and it linked similar documents to the same activity. Representative indicators included hashes for the exploit documents and infrastructure such as word-template.net, openxmlformat.org, ms-office.services, and template-openxml.com.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c49b4d370ad0dcd1e28ee8f525ac8e3… | 2022-12-07 | 2025-02-10 |
| HASH | 08f93351d0d3905bee5b0c2b9215d44… | 2022-12-07 | 2022-12-07 |
| HASH | af5fb99d3ff18bc625fb63f792ed7cd… | 2022-12-07 | 2022-12-07 |
| HASH | 926a947ea2b59d3e9a5a6875b4de2bd… | 2022-12-07 | 2022-12-07 |
| HASH | 56ca24b57c4559f834c190d50b0fe89… | 2022-12-07 | 2022-12-07 |
| HASH | 3bff571823421c013e79cc10793f238… | 2022-12-07 | 2022-12-07 |
| DOMAIN | template-openxml.com | 2022-12-07 | 2022-12-07 |
| DOMAIN | word-template.net | 2022-11-17 | 2022-12-07 |
| DOMAIN | ms-offices.com | 2022-11-17 | 2022-12-07 |