APT37-Linked Campaign Uses Phishing and Obfuscated Scripts to Deploy Python Backdoor

· Original article ↗

Summary

Genians details a suspected APT37-linked spear-phishing campaign that uses ZIP-delivered LNK files, obfuscated scripts, and a disguised Python bytecode payload to install a persistent backdoor for remote command execution.

Key points

  • Spear-phishing emails used lures including e-tickets, research-event invitations, and impersonation of defense and police officials to persuade recipients to open ZIP archives containing malicious LNK files.
  • Executing an LNK reconstructs obfuscated commands that invoke cmd.exe and PowerShell, download BAT scripts, and display a decoy document.
  • The scripts download a Python 3.10 embedded runtime, rename pythonw.exe, and execute a compiled Python payload disguised with a .cat extension.
  • The payload communicates with C2, receives and executes Python code, and returns execution results; a scheduled task configured to run every minute provides persistence.
  • Genians reports infrastructure, code, and operational similarities to previous activity and assesses the campaign as linked to APT37, while cautioning that attribution can be uncertain.
  • The report recommends behavior-based EDR monitoring for obfuscated command execution, LNK-to-script chains, suspicious downloads, abnormal Python execution, and scheduled-task creation.

Article Details

Attack Vectors
  • Spear-phishing emails delivered ZIP archives containing LNK files, using lures such as airline e-tickets, North Korea research events, and impersonation of defense or police officials.
  • LNK execution reconstructed obfuscated commands through environment-variable substring expansion, then used cmd.exe and PowerShell to download and execute staged BAT scripts.
  • The infection chain configured a Python runtime, disguised compiled Python bytecode as a .cat file, and used a scheduled task for recurring execution.
  • The backdoor communicated with a C2 server over HTTP, received Base64-encoded Python code, executed it, and returned execution results.
Defensive Notes
  • Use behavior-based EDR monitoring for LNK execution from archives, linked cmd.exe and PowerShell activity, and environment-variable substring-expansion obfuscation.
  • Monitor external downloads by curl.exe, Python runtime creation in public user paths, renamed pythonw.exe executables, and execution of Python bytecode with abnormal extensions.
  • Detect creation and repeated execution of scheduled tasks, especially tasks with names resembling legitimate system tasks.
  • Correlate process relationships, command lines, file creation locations, scheduled-task activity, and network events rather than relying only on changeable indicators.

Indicators of compromise

TypeIndicatorContext
DOMAINableinfo[.]co[.]krDomain associated with an IP address used as distribution infrastructure for malicious files.
DOMAINchoisy[.]frC2 domain identified in the campaign and linked to the same infrastructure as the cited IP address.
DOMAINezvm[.]krC2 domain listed among infrastructure used by related malicious files.
DOMAINfe01[.]co[.]krDomain listed in the article's IoC section as threat infrastructure.
DOMAINhaeundaejugong[.]comC2 domain used by the historical Chinotto information-stealing malware.
DOMAINhanainternational[.]netDomain hosting a webshell identified as malicious and used in related campaigns.
DOMAINintobiz[.]krC2 domain listed among infrastructure used by related malicious files.
DOMAINkmot[.]co[.]krC2 domain used to deliver the decoy document and BAT payload and to receive backdoor communications.
DOMAINkumdo[.]orgC2 domain used by the historical Chinotto information-stealing malware.
DOMAINluminix[.]krC2 domain listed among infrastructure used by related malicious files.
DOMAINprintory[.]krHost of a webshell used to download the Compiled Python bytecode payload.
DOMAINsjem[.]co[.]krC2 domain used in the historical APT37-linked Flash-exploitation activity.
DOMAINsunlin[.]orgC2 domain listed among infrastructure used by related malicious files.
DOMAINudcontest[.]comDomain used in a phishing attack and identified as hosting a webshell of the same type as those in related campaigns.
DOMAINversonnex74[.]frDomain hosting an attachment link used in a previously reported malicious campaign.
DOMAINycpatent[.]co[.]krDomain listed in the article's IoC section as threat infrastructure.
HOSTNAMEkjdnc[.]gp114[.]netC2 hostname listed among infrastructure used by related malicious files.
HOSTNAMEljs5950[.]cafe24[.]comC2 hostname listed among infrastructure used by related malicious files.
HOSTNAMEoxenhan1[.]cafe24[.]comHostname listed in the article's IoC section as threat infrastructure.
IPV4114[.]207[.]246[.]156IP address to which the malicious udcontest[.]com domain resolved.
IPV4121[.]78[.]88[.]88IP address associated in the article with the malicious C2 URL on haeundaejugong[.]com.
IPV4121[.]78[.]88[.]92IP address associated in the article with the malicious C2 URL on hanainternational[.]net.
IPV4121[.]78[.]88[.]93IP address associated in the article with the malicious C2 URL on attiferstudio[.]com.
IPV4183[.]111[.]174[.]69IP address listed in the article's IoC section as threat infrastructure.
IPV4211[.]169[.]73[.]104IP address associated in the article with the malicious C2 URL on sunlin[.]org.
IPV4211[.]239[.]157[.]126IP address listed in the article's IoC section as threat infrastructure.
IPV4218[.]150[.]78[.]198IP address listed in the article's IoC section as threat infrastructure.
IPV4220[.]73[.]160[.]23IP address listed in the article's IoC section as threat infrastructure.
IPV451[.]158[.]21[.]1IP address used with the identified C2 infrastructure, including choisy[.]fr.
MD509dabe5ab566e50ab4526504345af297MD5 hash listed in the article's IoC section as a threat indicator.
MD516d7be5ebc3c2ff1cffbb83b965fd4fbMD5 hash listed in the article's IoC section as a threat indicator.
MD51aa7751332710f4e963a708243d3d550MD5 hash listed in the article's IoC section as a threat indicator.
MD5255155bad9af5e2c6cf550ff2a95219dMD5 hash listed in the article's IoC section as a threat indicator.
MD533c97fc4eacd73addbae9e6cde54a77dMD5 hash listed in the article's IoC section as a threat indicator.
MD57922f91281e8b0fe00518d05bf295b4aMD5 hash listed in the article's IoC section as a threat indicator.
MD5804d12b116bb40282fbf245db885c093MD5 hash listed in the article's IoC section as a threat indicator.
MD5abbb362cdfe14b56b3a13a2a55937ee4MD5 hash listed in the article's IoC section as a threat indicator.
MD5b5f9cd67cb32f44c138c382e17b06fd6MD5 hash listed in the article's IoC section as a threat indicator.
MD5f7b2e0cebd7793c8cfee2c7c5b93df9cMD5 hash listed in the article's IoC section as a threat indicator.
MD5fcb97f87905a33af565b0a4f4e884d61MD5 hash listed in the article's IoC section as a threat indicator.

MITRE ATT&CK

CVE

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles