Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign

2026-05-10 Genians

https://www.genians.co.kr/en/blog/threat_intelligence/python

Thumbnail for Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign

Genians links this campaign to suspected APT37 activity using spear-phishing emails that deliver ZIP archives containing malicious LNK files. The lures included airline e-ticket confirmations, North Korea research event invitations, and impersonation of defense and police officials to induce execution. Once opened, the LNK reconstructs obfuscated commands through environment-variable substring expansion, launches batch files, and downloads additional payloads in a multi-stage chain. The final payload is Compiled Python bytecode disguised with a .cat extension and analyzed as a Python-runtime remote command execution backdoor, with overlaps to prior deepfake-themed military ID forgery activity and related C2 infrastructure abuse.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 211.239.157.126 2026-06-14 2026-06-14
DOMAIN fe01.co.kr 2026-06-14 2026-06-14
IPv4 218.150.78.198 2026-06-14 2026-06-14
DOMAIN choisy.fr 2026-05-10 2026-05-10
IPv4 220.73.160.23 2026-05-10 2026-05-10
DOMAIN printory.kr 2026-05-10 2026-05-10
DOMAIN ycpatent.co.kr 2026-05-10 2026-05-10
DOMAIN kmot.co.kr 2026-05-10 2026-05-10
IPv4 183.111.174.69 2026-05-10 2026-05-10
DOMAIN oxenhan1.cafe24.com 2026-05-10 2026-05-10
HASH 7922f91281e8b0fe00518d05bf295b4a 2026-05-10 2026-05-10
HASH 16d7be5ebc3c2ff1cffbb83b965fd4fb 2026-05-10 2026-05-10
HASH 1aa7751332710f4e963a708243d3d550 2026-05-10 2026-05-10
HASH f7b2e0cebd7793c8cfee2c7c5b93df9c 2026-05-10 2026-05-10
HASH b5f9cd67cb32f44c138c382e17b06fd6 2026-05-10 2026-05-10
HASH abbb362cdfe14b56b3a13a2a55937ee4 2026-05-10 2026-05-10
HASH 255155bad9af5e2c6cf550ff2a95219d 2026-05-10 2026-05-10
HASH 33c97fc4eacd73addbae9e6cde54a77d 2025-09-14 2025-09-14
HASH fcb97f87905a33af565b0a4f4e884d61 2025-09-14 2025-09-14
HASH 09dabe5ab566e50ab4526504345af297 2025-09-14 2025-09-14
IPv4 51.158.21.1 2025-09-14 2025-09-14
HASH 804d12b116bb40282fbf245db885c093 2022-08-29 2022-08-29

Related Actors

Related Reports

« Back