Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks

2025-12-21 Genians

https://www.genians.co.kr/en/blog/threat_intelligence/dll

Thumbnail for Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks

Genians attributes Operation Artemis to APT37 and describes spear-phishing that used malicious HWP/HWPX documents against people engaged with North Korea, human rights, abduction issues, interviews, seminars, and related policy topics. The attacker impersonated credible figures such as university professors and Korean TV writers, sometimes building trust through normal conversation before delivering an HWP lure disguised as an invitation, questionnaire, event guide, or interview request. Execution began when a victim clicked an embedded OLE object presented as a hyperlink, leading to creation of a malicious version.dll in %TEMP% and abuse of legitimate Sysinternals VolumeId utilities for DLL side-loading. The campaign combined HWP OLE abuse, legitimate-process masquerading, steganography-based RoKRAT deployment, and repeated lure evolution over several months, underscoring the continued use of HWP as a North Korea-linked attack surface in South Korean targeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d287dcaeaf17c9dae8a253994502ee58 2025-12-21 2025-12-21
HASH 7e8c24bb3b50d68227ff2b7193d548dd 2025-12-21 2025-12-21
HASH 2f3dff7779795fc01291b0a31d723aca 2025-12-21 2025-12-21
HASH c0cac70c93d213d113001e3410c24fd2 2025-12-21 2025-12-21
HASH f3603f68aadc8bc1ea8939132f0d5252 2025-12-21 2025-12-21
HASH ea95109b608841d2f99a25bd2646ff43 2025-12-21 2025-12-21
HASH d2b2c6646535a62e4c005613d6a036f0 2025-12-21 2025-12-21
HASH e726b59f96ab8360f323469d72b8b617 2025-12-21 2025-12-21
HASH 31662a24560b3fe1f34f0733e65509ff 2025-12-21 2025-12-21
HASH 17171c644307b17d231ad404e25f08b1 2025-12-21 2025-12-21
HASH f13a4834e3e1613857b84a1203e2e182 2025-12-21 2025-12-21
HASH ad3433f5f64abdec7868a52341f14196 2025-12-21 2025-12-21
HASH a196fb11a423076f66f5e4b2d02813a9 2025-12-21 2025-12-21
HASH 8e4a99315a3ef443928ef25d90f84a09 2025-12-21 2025-12-21
EMAIL [email protected] 2024-04-23 2025-12-21

Related Actors

Related Reports

« Back