Executive Summary
Genians Security Center has identified a sophisticated threat campaign attributed to APT37 (also known as the State Intelligence Bureau) targeting defense, security, and North Korea research sectors. The campaign employs high-pressure social engineering lures—including airline e-tickets, police impersonation, and AI-driven deepfake military IDs—to induce victims into executing malicious LNK files.
Technically, the actor utilizes environment variable-based substring expansion to obfuscate command-line activities and evades detection by abusing legitimate tools like curl.exe and the Python Embed package. The final payload is a compiled Python backdoor (Chinotto family variant) that provides persistent remote command execution capabilities. This activity demonstrates a high degree of TTP continuity with previous APT37 operations, including the reuse of the 'Lailey' account and specific C2 infrastructure patterns dating back to 2020.
The use of legitimate software environments (Python runtimes) and the disguise of malicious bytecode as system files (.cat) highlights a strategic shift toward evading traditional signature-based defenses, necessitating robust behavior-based EDR monitoring.
