216.73.217.22

Operation HanKook Phantom: Spear-Phishing Campaign

· Published 29/08/2025 13:41 · Modified 29/08/2025 15:49

Export JSON

Essential information

Published
29/08/2025 13:41
Modified
29/08/2025 15:49
Tags
2025-08-29 cloud services data exfiltration espionage fileless lnk files north korea powershell rokrat south korea spear-phishing
Related entities
1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 11 others

Description

APT37, a North Korean state-backed cyber group, has launched a sophisticated campaign targeting South Korean government sectors, research institutions, and academics. The attackers use malicious disguised as legitimate documents to deliver a multi-stage infection chain. This includes execution, in-memory loading of encrypted payloads, and covert mechanisms. The campaign, dubbed Operation HanKook Phantom, demonstrates APT37's continued focus on intelligence gathering and long-term against South Korean targets. The attackers leverage for command-and-control and employ various techniques to evade detection, highlighting the persistent threat posed by North Korean state-sponsored actors.

External references