216.73.217.22

Analysis of APT37 Attack Case Disguised as a Think Tank for National Security Strategy in South Korea (Operation ToyBox Story)

· Published 06/06/2025 11:02 · Modified 08/06/2025 16:56

Export JSON

Essential information

Published
06/06/2025 11:02
Modified
08/06/2025 16:56
Tags
2025-06-06 CVE-2022-41128 cloud c2 fileless attacks lnk files national security north korea rokrat south korea spear-phishing
Related entities
1 observables, 1 intrusion sets (apt), 18 techniques (mitre), 1 others

Description

APT37, a North Korean state-sponsored hacking group, launched a spear phishing campaign targeting activists focused on . The attack involved emails with Dropbox links to malicious , which when executed, activated additional malware. The group utilized legitimate cloud services as Command and Control servers, a tactic known as 'Living off Trusted Sites.' The malware, identified as , collected system information, captured screenshots, and exfiltrated data to cloud-based C2 servers. The campaign, named 'Operation: ToyBox Story,' employed sophisticated techniques including and multiple encryption layers to evade detection. The threat actors impersonated academic events and used decoy documents to lure targets, highlighting the need for advanced endpoint detection and response solutions.

External references