APT37 Python Backdoor and Deepfake Impersonation Campaign
Score: 8/10

APT37 Python Backdoor and Deepfake Impersonation Campaign

APT37 utilizes obfuscated LNK files and multi-stage batch scripts to deploy a Python-based remote access backdoor disguised as a .cat file.

Executive Summary

Genians Security Center has identified a sophisticated threat campaign attributed to APT37 (also known as the State Intelligence Bureau) targeting defense, security, and North Korea research sectors. The campaign employs high-pressure social engineering lures—including airline e-tickets, police impersonation, and AI-driven deepfake military IDs—to induce victims into executing malicious LNK files.

Technically, the actor utilizes environment variable-based substring expansion to obfuscate command-line activities and evades detection by abusing legitimate tools like curl.exe and the Python Embed package. The final payload is a compiled Python backdoor (Chinotto family variant) that provides persistent remote command execution capabilities. This activity demonstrates a high degree of TTP continuity with previous APT37 operations, including the reuse of the 'Lailey' account and specific C2 infrastructure patterns dating back to 2020.

The use of legitimate software environments (Python runtimes) and the disguise of malicious bytecode as system files (.cat) highlights a strategic shift toward evading traditional signature-based defenses, necessitating robust behavior-based EDR monitoring.

Key Details

Threat Name

APT37 Python Backdoor Campaign

Affects

Adobe Flash Player, Hancom Office (HWP)

Adversary

APT37

Malware/Tools

Chinotto, settingenv.cat

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources