{"id":1715,"date":"2025-02-03T10:03:36","date_gmt":"2025-02-03T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/03\/apt37-hackers-abusing-group-chats-to-attack-via-malicious-lnk-file\/"},"modified":"2025-02-03T10:03:36","modified_gmt":"2025-02-03T10:03:36","slug":"apt37-hackers-abusing-group-chats-to-attack-via-malicious-lnk-file","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/03\/apt37-hackers-abusing-group-chats-to-attack-via-malicious-lnk-file\/","title":{"rendered":"APT37 Hackers Abusing Group Chats To Attack Via Malicious LNK File"},"content":{"rendered":"<p>    APT37 Hackers Abusing Group Chats To Attack Via Malicious LNK File<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The North Korean state-sponsored hacking group APT37 (aka ScarCruft, Reaper), has been identified leveraging group chat platforms to distribute malicious LNK files.<\/p>\n<p>This latest tactic highlights the group\u2019s evolving methods to infiltrate systems and exfiltrate sensitive data.<\/p>\n<p>APT37\u2019s recent campaign involves sending malicious LNK files through group chats on popular messaging platforms.<\/p>\n<p>These files are often embedded in ZIP archives and disguised with familiar icons and filenames to deceive targets.<\/p>\n<p>For instance, attackers used filenames such as \u201cChanges in Chinese Government\u2019s North Korea Policy.zip\u201d to lure victims into opening the file.<\/p>\n<p>Analysts at Genians<a href=\"https:\/\/www.genians.co.kr\/blog\/threat_intelligence\/k-messenger\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> identified<\/a> that once executed, the LNK file triggers a PowerShell command that initiates a multi-stage infection chain.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhS-Hfc78X1M0kfb6stjzG1By9lAASDVpsHWCN6xjOLYkL1HN9um_Tr5bIteGl6WU9poc347uNslRdPl_nxVLHe6ciyoD4aEn-mQ8c0Zg02aMaoe5DsKg3HGUk_Ui2nntxiqVQs6ODPWCq7rLqtT_BB1y04rIe0z10tl6UxIBWAYEZ6KtUNmp5dk1uS2J0\/s16000\/Attack%2520Timeline%2520Flowchart%2520%28Source%2520-%2520Genians%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack Timeline Flowchart (Source \u2013 Genians)<\/figcaption><\/figure>\n<\/div>\n<p>The command decodes and executes embedded scripts, often leading to the deployment of the RokRAT malware.<\/p>\n<p>RokRAT is a powerful <a href=\"https:\/\/cybersecuritynews.com\/darkcomet-rat\/\" target=\"_blank\" rel=\"noreferrer noopener\">remote access trojan<\/a> (RAT) capable of data exfiltration, screen capturing, and remote command execution.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMOffpwsw1Oq_Aw?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWHzuATJbL0jfBtY0zgivXt29-B5eafGLmfyS44Nak8D4b5J_m06XopxmSs6FUypuTe6L6bM8LZCjuMXhLKtOSWFsddBtBo8W7Qq_kVB-KASGCgVms4SVq9sx3My_HHLwftfeOKZ6fCL0rREosRHLH-ACPTkE5jv7Zlo49SkHq-5svb9AF-5ggMS2-Sxo\/s16000\/Find%2520this%2520story%2520interesting%21%2520Follow%2520us%2520on%2520Google%2520News.webp?ssl=1\" alt=\"\"><\/a><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Attack Analysis<\/strong><\/h2>\n<p>The malicious LNK files contain embedded PowerShell commands that execute hidden scripts.<\/p>\n<p>This script reads a malicious payload from a temporary file (<code>bus.dat<\/code>), decodes it, and executes it in memory.<\/p>\n<p>Such fileless execution techniques evade traditional <a href=\"https:\/\/cybersecuritynews.com\/understanding-false-positives-in-antivirus-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus detection<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgP9IasUn-3iNBh0oFsMY4v1rRvJqb1RhkvLGm5oTqua6u0iLrFaEDddhkspy_tMVAy3GYtJH0ALMmatkZhE1N5oalcecEZuaIU95SQRBu8mXRgl_77eu20NtPTv3R-oeIcTamNX9MUcgL_ZvWyAC5Xpc1eQxLasM5OKl7oRNQPNN3_K78ZRYwI75AQjUc\/s16000\/Attack%2520vector%2520%28Source%2520-%2520Genians%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack vector (Source \u2013 Genians)<\/figcaption><\/figure>\n<\/div>\n<p>APT37 employs social engineering tactics by impersonating trusted individuals or organizations. For example, attackers have used themes like geopolitical reports or lecture materials as bait.<\/p>\n<p>These files often appear legitimate but contain embedded OLE objects or scripts that activate upon interaction.<\/p>\n<p>The primary payload in these attacks is often RokRAT or similar malware variants. Key features include:-<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Data Exfiltration:<\/strong> Stealing credentials, screenshots, and sensitive files.<\/li>\n<li>\n<strong>Remote Control:<\/strong> Executing commands on infected systems.<\/li>\n<li>\n<strong>Persistence:<\/strong> Dropping additional payloads into startup folders for execution upon reboot.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/cybersecuritynews.com\/apt37-hackers-actively-scanning-targets\/\" target=\"_blank\" rel=\"noreferrer noopener\">APT37<\/a> also leverages cloud services like pCloud and OneDrive for command-and-control (C2) operations, further complicating detection efforts.<\/p>\n<p>To defend against such threats, deploy endpoint detection and response (EDR) solutions capable of detecting abnormal behaviors, such as fileless malware execution.<\/p>\n<p>In addition, educate users about the risks of opening unsolicited files, even from trusted contacts, and disable the \u201cHide extensions for known file types\u201d setting to easily identify suspicious double extensions like \u201c.pdf.lnk.\u201d<\/p>\n<p>APT37\u2019s use of group chats as a delivery mechanism underscores their adaptability and persistence in targeting South Korean entities and beyond. Organizations must remain vigilant and adopt proactive <a href=\"https:\/\/cybersecuritynews.com\/non-negotiable-for-payroll-compliance\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity measures<\/a> to counter such advanced persistent threats.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Indicators of Compromise (IoCs)<\/strong><\/h2>\n<p>Security researchers have identified several IoCs related to this campaign:-<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>MD5 Hashes:<\/strong> <code>1a70a013a56673f25738cf145928d0f5<\/code>, <code>1c3bb05a03834f56b0285788d988aae4<\/code>\n<\/li>\n<li>\n<strong>C2 Servers:<\/strong> <code>172.86.115[.]125<\/code>, <code>mailattachmentimageurlxyz[.]site<\/code>\n<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code><strong><code><strong>Are you from SOC\/DFIR Teams? \u2013\u00a0Analyse Malware Files &amp; Links with ANY.RUN Sandox\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/demo\/?utm_source=li_csn&amp;utm_medium=post&amp;utm_campaign=meme&amp;utm_content=demo&amp;utm_term=030225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apt37-hackers-abusing-group-chats\/\">APT37 Hackers Abusing Group Chats To Attack Via Malicious LNK File<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apt37-hackers-abusing-group-chats\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT37 Hackers Abusing Group Chats To Attack Via Malicious LNK File The North Korean state-sponsored hacking group APT37 (aka ScarCruft, Reaper), has been identified leveraging group chat platforms to distribute malicious LNK files. This latest tactic highlights the group\u2019s evolving methods to infiltrate systems and exfiltrate sensitive data. APT37\u2019s recent campaign involves sending malicious LNK [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,63,700],"tags":[130],"class_list":["post-1715","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security-news","category-cyberattack-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1715"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=1715"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/1715\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=1715"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=1715"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=1715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}