Operation HanKook Phantom: APT37 Spear-Phishing Campaign

2025-08-29 Seqrite

https://www.seqrite.com/blog/operation-hankook-phantom-north-korean-apt37-targeting-south-korea/

Thumbnail for Operation HanKook Phantom: APT37 Spear-Phishing Campaign

Seqrite links Operation HanKook Phantom to APT37, a North Korean state-backed espionage actor also known as InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, and Ricochet Chollima. The campaign used a National Intelligence Research Society newsletter decoy and a disguised Windows LNK file to target South Korean national-security, academic, policy, labor, and energy-related circles. Executing the LNK launched embedded PowerShell that extracted a decoy PDF and multiple payloads, ran a batch script, decoded an XOR-encrypted payload, and executed it in memory through Windows API calls. The final ROKRAT payload fingerprinted victim systems, checked for virtualized or restricted environments, captured screenshots, enumerated files, ran commands, downloaded additional payloads, and exfiltrated data. Its command-and-control design used cloud services including pCloud, Yandex, and Dropbox, making the operation relevant for defenders monitoring spear-phishing, fileless PowerShell execution, and cloud-based C2 abuse.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1aec7b1227060a987d5cb6f17782e76e 2025-08-29 2026-01-14
HASH d035135e190fb6121faa7630e4a45eed 2025-08-29 2026-01-14
HASH 591b2aaf1732c8a656b5c602875cbdd9 2025-08-29 2026-01-14
HASH 443a00feeb3beaea02b2fbcd4302a3c9 2025-08-03 2026-01-14
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
HASH 051517b5b685116c2f4f1e6b535eb4cb 2025-08-29 2025-08-29
HASH 2dc20d55d248e8a99afbe5edaae5d2fc 2025-08-29 2025-08-29
HASH f34fa3d0329642615c17061e252c6afe 2025-08-29 2025-08-29
HASH da05d6ab72290ca064916324cbc86bab 2025-08-29 2025-08-29
HASH cc1522fb2121cf4ae57278921a5965da 2025-08-29 2025-08-29
URL http://daily.alltop.asia/blog/a… 2025-08-29 2025-08-29
URL http://daily.alltop.asia/blog/a… 2025-08-29 2025-08-29
DOMAIN daily.alltop.asia 2025-08-29 2025-08-29
HASH f6d72abf9ca654a20bbaf23ea1c10a55 2025-06-09 2025-08-29
URL https://cloud-api.yandex.net/v1… 2025-03-10 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/uploadfi… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/getfilel… 2024-04-03 2025-08-29
URL https://api.pcloud.com/listfold… 2024-04-03 2025-08-29
URL https://api.dropboxapi.com/2/fi… 2023-01-16 2025-08-29
URL https://api.dropboxapi.com/2/fi… 2018-09-21 2025-08-29
URL https://api.pcloud.com/deletefi… 2018-09-21 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29

Related Actors

Related Reports

« Back