Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks
2025-12-21 • Genians •
Genians attributes Operation Artemis to APT37 and describes spear-phishing that used malicious HWP/HWPX documents against people engaged with North Korea, human rights, abduction issues, interviews, seminars, and related policy topics. The attacker impersonated credible figures such as university professors and Korean TV writers, sometimes building trust through normal conversation before delivering an HWP lure disguised as an invitation, questionnaire, event guide, or interview request. Execution began when a victim clicked an embedded OLE object presented as a hyperlink, leading to creation of a malicious version.dll in %TEMP% and abuse of legitimate Sysinternals VolumeId utilities for DLL side-loading. The campaign combined HWP OLE abuse, legitimate-process masquerading, steganography-based RoKRAT deployment, and repeated lure evolution over several months, underscoring the continued use of HWP as a North Korea-linked attack surface in South Korean targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d287dcaeaf17c9dae8a253994502ee58 | 2025-12-21 | 2025-12-21 |
| HASH | 7e8c24bb3b50d68227ff2b7193d548dd | 2025-12-21 | 2025-12-21 |
| HASH | 2f3dff7779795fc01291b0a31d723aca | 2025-12-21 | 2025-12-21 |
| HASH | c0cac70c93d213d113001e3410c24fd2 | 2025-12-21 | 2025-12-21 |
| HASH | f3603f68aadc8bc1ea8939132f0d5252 | 2025-12-21 | 2025-12-21 |
| HASH | ea95109b608841d2f99a25bd2646ff43 | 2025-12-21 | 2025-12-21 |
| HASH | d2b2c6646535a62e4c005613d6a036f0 | 2025-12-21 | 2025-12-21 |
| HASH | e726b59f96ab8360f323469d72b8b617 | 2025-12-21 | 2025-12-21 |
| HASH | 31662a24560b3fe1f34f0733e65509ff | 2025-12-21 | 2025-12-21 |
| HASH | 17171c644307b17d231ad404e25f08b1 | 2025-12-21 | 2025-12-21 |
| HASH | f13a4834e3e1613857b84a1203e2e182 | 2025-12-21 | 2025-12-21 |
| HASH | ad3433f5f64abdec7868a52341f14196 | 2025-12-21 | 2025-12-21 |
| HASH | a196fb11a423076f66f5e4b2d02813a9 | 2025-12-21 | 2025-12-21 |
| HASH | 8e4a99315a3ef443928ef25d90f84a09 | 2025-12-21 | 2025-12-21 |
| [email protected] | 2024-04-23 | 2025-12-21 |