APT37 Hackers Use Fake Academic Invites to Distribute Malicious LNK Files via Dropbox Platform

Cybersecurity researchers at Genians Security Center (GSC) sounded the alarm over a sophisticated spear phishing campaign orchestrated by the North Korea-linked threat actor APT37, also known as ScarCruft.

This state-sponsored group leveraged fake academic invitations purporting to originate from leading South Korean national security think tanks, luring target recipients including North Korea-focused activists and policy experts into opening well-crafted phishing emails.

The attackers referenced real-world events, such as a high-profile “Trump 2.0 Era” conference, to bolster authenticity and entice engagement.

North Korean Threat Group Exploits Cloud Services

The attack chain began with a phishing email containing a Dropbox link to a compressed ZIP archive. Inside the ZIP was a malicious Windows shortcut (LNK) file.

Upon extraction and execution, this LNK file would trigger a fileless malware infection via PowerShell scripts deploying a sophisticated payload known as RoKRAT, a proven remote access trojan (RAT) already associated with past APT37 intrusions.

APT37’s use of Dropbox as the command-and-control (C2) channel represents a continued evolution of “Living off Trusted Sites” (LoTS) attack methodology.

This approach mirrors “Living off the Land” techniques but abuses legitimate, globally trusted platforms such as Dropbox, pCloud, Yandex, OneDrive, and Google Drive to manage C2 communication and data exfiltration.

Malicious LNK Files
Malicious LNK File Structure

In these 2025 campaigns, Dropbox handled the upload, download, and deletion of payloads, while access tokens tied to Russian Yandex accounts helped the operators obscure attribution.

Technical analysis revealed that the LNK file, masquerading as an innocuous document (e.g., “To North Korean Soldiers Deployed to the Russian Battlefield.hwp”), executed hidden PowerShell commands designed to evade endpoint defenses.

The embedded commands launched decoy documents to distract the victim while simultaneously executing batched scripts in the background.

These scripts loaded multi-stage files in the %Temp% directory, using XOR encoding and fileless injection techniques to decrypt and execute RoKRAT malware directly in memory, thereby minimizing forensic traces.

Operation “ToyBox Story”

RoKRAT, the final payload, immediately harvested comprehensive system information, including OS version, device identifiers, manufacturer details, BIOS version, user names, and execution paths.

Malicious LNK Files
Flowchart of the APT37 Attack

It proceeded to exfiltrate this data, along with live screenshots, via encrypted channels back to the Dropbox C2 infrastructure.

Notably, the malware’s encryption routines combined XOR obfuscation with AES-CBC-128, and the AES keys themselves were RSA-protected for additional complexity.

The spear phishing operation was broad in scope, with multiple observed variants. In one, attackers disguised the ZIP archive as an event poster; in another, they used content themes referencing sensitive North Korean troop deployments in Russia.

All cases employed the same RoKRAT backdoor, as confirmed by static and behavioral malware similarity analyses using tooling such as Capa and MITRE ATT&CK mapping.

GSC’s investigation traced threat infrastructure to several Yandex and Gmail accounts, some of which appeared on LinkedIn, though attribution remains under review.

APT37 continues to refine its tactics to evade EDR and AV tools, leaning heavily on fileless malware execution and cloud-based C2 to frustrate traditional enterprise detection methods.

Mitigation recommendations stress the necessity of real-time endpoint monitoring, anomaly-based threat hunting, and caution when handling unsolicited ZIP or LNK files especially those distributed via cloud storage links.

GSC’s Genian EDR demonstrated efficacy in detecting and isolating these threats, providing actionable forensics such as parent-child process trees and PowerShell command-line traces essential for incident response.

Indicators of Compromise (IOC)

TypeDetails
MD581c08366ea7fc0f933f368b120104384, 723f80d1843315717bc56e9e58e89be5, 7822e53536c1cf86c3e44e31e77bd088, 324688238c42d7190a2b50303cbc6a3c, a635bd019674b25038cd8f02e15eebd2, beeaca6a34fb05e73a6d8b7d2b8c2ee3, d5d48f044ff16ef6a4d5bde060ed5cee, d77c8449f1efc4bfb9ebff496442bbbc, 2f431c4e65af9908d2182c6a093bf262, 7cc8ce5374ff9eacd38491b75cbedf89, 8f339a09f0d0202cfaffbd38469490ec, 46ca088d5c052738d42bbd6231cc0ed5
C2 IPs89.147.101[.]65, 89.147.101[.]71, 37.120.210[.]2
E-mailsrolf.gehrung@yandex.com, ekta.sahasi@yandex.com, gursimran.bindra@yandex.com, sneha.geethakrishnan@yandex.com, tanessha.samuel@gmail.com, tianling0315@gmail.com, w.sarah0808@gmail.com, softpower21cs@gmail.com, sandozmessi@gmail.com, tiger.man.1999@mail.ru, navermail_noreply@mail.ru
Cloud C2api.pcloud[.]com, cloud-api.yandex[.]net, api.dropboxapi[.]com

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories