APT37-Linked Campaign Uses Phishing and Obfuscated Scripts to Deploy Python Backdoor

Summary
Genians details a suspected APT37-linked spear-phishing campaign that uses ZIP-delivered LNK files, obfuscated scripts, and a disguised Python bytecode payload to install a persistent backdoor for remote command execution.
Key points
- Spear-phishing emails used lures including e-tickets, research-event invitations, and impersonation of defense and police officials to persuade recipients to open ZIP archives containing malicious LNK files.
- Executing an LNK reconstructs obfuscated commands that invoke cmd.exe and PowerShell, download BAT scripts, and display a decoy document.
- The scripts download a Python 3.10 embedded runtime, rename pythonw.exe, and execute a compiled Python payload disguised with a .cat extension.
- The payload communicates with C2, receives and executes Python code, and returns execution results; a scheduled task configured to run every minute provides persistence.
- Genians reports infrastructure, code, and operational similarities to previous activity and assesses the campaign as linked to APT37, while cautioning that attribution can be uncertain.
- The report recommends behavior-based EDR monitoring for obfuscated command execution, LNK-to-script chains, suspicious downloads, abnormal Python execution, and scheduled-task creation.
Article Details
- Attack Vectors
- Spear-phishing emails delivered ZIP archives containing LNK files, using lures such as airline e-tickets, North Korea research events, and impersonation of defense or police officials.
- LNK execution reconstructed obfuscated commands through environment-variable substring expansion, then used cmd.exe and PowerShell to download and execute staged BAT scripts.
- The infection chain configured a Python runtime, disguised compiled Python bytecode as a .cat file, and used a scheduled task for recurring execution.
- The backdoor communicated with a C2 server over HTTP, received Base64-encoded Python code, executed it, and returned execution results.
- Defensive Notes
- Use behavior-based EDR monitoring for LNK execution from archives, linked cmd.exe and PowerShell activity, and environment-variable substring-expansion obfuscation.
- Monitor external downloads by curl.exe, Python runtime creation in public user paths, renamed pythonw.exe executables, and execution of Python bytecode with abnormal extensions.
- Detect creation and repeated execution of scheduled tasks, especially tasks with names resembling legitimate system tasks.
- Correlate process relationships, command lines, file creation locations, scheduled-task activity, and network events rather than relying only on changeable indicators.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | ableinfo[.]co[.]kr | Domain associated with an IP address used as distribution infrastructure for malicious files. |
| DOMAIN | choisy[.]fr | C2 domain identified in the campaign and linked to the same infrastructure as the cited IP address. |
| DOMAIN | ezvm[.]kr | C2 domain listed among infrastructure used by related malicious files. |
| DOMAIN | fe01[.]co[.]kr | Domain listed in the article's IoC section as threat infrastructure. |
| DOMAIN | haeundaejugong[.]com | C2 domain used by the historical Chinotto information-stealing malware. |
| DOMAIN | hanainternational[.]net | Domain hosting a webshell identified as malicious and used in related campaigns. |
| DOMAIN | intobiz[.]kr | C2 domain listed among infrastructure used by related malicious files. |
| DOMAIN | kmot[.]co[.]kr | C2 domain used to deliver the decoy document and BAT payload and to receive backdoor communications. |
| DOMAIN | kumdo[.]org | C2 domain used by the historical Chinotto information-stealing malware. |
| DOMAIN | luminix[.]kr | C2 domain listed among infrastructure used by related malicious files. |
| DOMAIN | printory[.]kr | Host of a webshell used to download the Compiled Python bytecode payload. |
| DOMAIN | sjem[.]co[.]kr | C2 domain used in the historical APT37-linked Flash-exploitation activity. |
| DOMAIN | sunlin[.]org | C2 domain listed among infrastructure used by related malicious files. |
| DOMAIN | udcontest[.]com | Domain used in a phishing attack and identified as hosting a webshell of the same type as those in related campaigns. |
| DOMAIN | versonnex74[.]fr | Domain hosting an attachment link used in a previously reported malicious campaign. |
| DOMAIN | ycpatent[.]co[.]kr | Domain listed in the article's IoC section as threat infrastructure. |
| HOSTNAME | kjdnc[.]gp114[.]net | C2 hostname listed among infrastructure used by related malicious files. |
| HOSTNAME | ljs5950[.]cafe24[.]com | C2 hostname listed among infrastructure used by related malicious files. |
| HOSTNAME | oxenhan1[.]cafe24[.]com | Hostname listed in the article's IoC section as threat infrastructure. |
| IPV4 | 114[.]207[.]246[.]156 | IP address to which the malicious udcontest[.]com domain resolved. |
| IPV4 | 121[.]78[.]88[.]88 | IP address associated in the article with the malicious C2 URL on haeundaejugong[.]com. |
| IPV4 | 121[.]78[.]88[.]92 | IP address associated in the article with the malicious C2 URL on hanainternational[.]net. |
| IPV4 | 121[.]78[.]88[.]93 | IP address associated in the article with the malicious C2 URL on attiferstudio[.]com. |
| IPV4 | 183[.]111[.]174[.]69 | IP address listed in the article's IoC section as threat infrastructure. |
| IPV4 | 211[.]169[.]73[.]104 | IP address associated in the article with the malicious C2 URL on sunlin[.]org. |
| IPV4 | 211[.]239[.]157[.]126 | IP address listed in the article's IoC section as threat infrastructure. |
| IPV4 | 218[.]150[.]78[.]198 | IP address listed in the article's IoC section as threat infrastructure. |
| IPV4 | 220[.]73[.]160[.]23 | IP address listed in the article's IoC section as threat infrastructure. |
| IPV4 | 51[.]158[.]21[.]1 | IP address used with the identified C2 infrastructure, including choisy[.]fr. |
| MD5 | 09dabe5ab566e50ab4526504345af297 | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | 16d7be5ebc3c2ff1cffbb83b965fd4fb | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | 1aa7751332710f4e963a708243d3d550 | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | 255155bad9af5e2c6cf550ff2a95219d | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | 33c97fc4eacd73addbae9e6cde54a77d | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | 7922f91281e8b0fe00518d05bf295b4a | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | 804d12b116bb40282fbf245db885c093 | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | abbb362cdfe14b56b3a13a2a55937ee4 | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | b5f9cd67cb32f44c138c382e17b06fd6 | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | f7b2e0cebd7793c8cfee2c7c5b93df9c | MD5 hash listed in the article's IoC section as a threat indicator. |
| MD5 | fcb97f87905a33af565b0a4f4e884d61 | MD5 hash listed in the article's IoC section as a threat indicator. |
MITRE ATT&CK
T1027.010 · Command ObfuscationCommands were concealed with environment-variable substring expansion and reconstructed at runtime.T1036.004 · Masquerade Task or ServiceThe scheduled task name was chosen to resemble a legitimate Microsoft-related system task.T1036.008 · Masquerade File TypeCompiled Python bytecode was disguised with a .cat extension to resemble a Windows security catalog file.T1053.005 · Scheduled TaskA scheduled task named MicrosoftMusicLibrariesPackageTaskMachine repeatedly ran the disguised Python payload.T1059.001 · PowerShellThe reconstructed command invoked PowerShell to control follow-up downloads and execution.T1059.003 · Windows Command ShellThe LNK invoked cmd.exe to reconstruct and run obfuscated commands.T1059.006 · PythonThe backdoor executed Python code received from the C2 server through exec().T1071.001 · Web ProtocolsThe backdoor used HTTP requests and POST data to exchange commands and results with its C2 server.T1105 · Ingress Tool TransferThe scripts downloaded BAT files, a Python runtime package, and the disguised bytecode payload from remote infrastructure.T1204.002 · Malicious FileThe infection chain began when the recipient extracted the archive and executed its LNK file.T1566.001 · Spearphishing AttachmentSpear-phishing emails delivered ZIP archives containing malicious LNK files as attachments.
CVE
Threat Actors
Malware
Vendors
AdobeIn 2020, the APT37 group has conducted attacks by embedding OLE objects in HWP document files and using them to trigger CVE-2018-15982, a vulnerability in Adobe Flash Player.GeniansGenians Security Center identified a threat campaign suspected of being associated with APT37 that combines an obfuscated batch file command invocation technique with Compiled Python-based malware.
Products
Adobe Flash PlayerIn 2020, the APT37 group has conducted attacks by embedding OLE objects in HWP document files and using them to trigger CVE-2018-15982, a vulnerability in Adobe Flash Player.Genian Insights EIntegrated Response Strategy with "Genian Insights E" Microsoft WindowsAt the time, the APT37 group used a wide range of malicious file formats, including Windows help files (CHM), HTML application files (HTA), Hancom Office document files (HWP), Microsoft Excel add-in files (XLL),Python EmbedIt then created the C:\Users\Public\Music\MusicLibrariesPackage path and extracted the ZIP file into that directory to configure a Python Embed execution environment.
Tools
cmd.exeInstead, an obfuscated command containing environment variable-based substring expansion is first executed through cmd.exe.curl.exeThe restored PowerShell syntax showed an attempt to copy C:\Windows\System32\curl.exe, which exists in a normal system path, to the %TEMP% path as RpJjgMB.exe.PowerShellWhen an LNK shortcut file is executed, PowerShell searches the current path for a ".lnk" file of a specific size, extracts data from a designated offset, saves it as "_ms3360.bat" in the temporary path ("%TEMP%"), andschtasksInternally, it was configured to reassemble and execute commands such as curl, mkdir, tar, del, ren, and schtasks.
Countries
FranceIn this case, a "cafe24[.]com" sender and a C2 server based on "choisy[.]fr" in France were also identified.North KoreaThemes designed to arouse curiosity were used, including airline e-tickets, invitations to North Korea research events, and impersonation of defense and police officialsSouth Korea