Cybersecurity researchers at Genians Security Center (GSC) sounded the alarm over a sophisticated spear phishing campaign orchestrated by the North Korea-linked threat actor APT37, also known as ScarCruft.
This state-sponsored group leveraged fake academic invitations purporting to originate from leading South Korean national security think tanks, luring target recipients including North Korea-focused activists and policy experts into opening well-crafted phishing emails.
The attackers referenced real-world events, such as a high-profile “Trump 2.0 Era” conference, to bolster authenticity and entice engagement.
North Korean Threat Group Exploits Cloud Services
The attack chain began with a phishing email containing a Dropbox link to a compressed ZIP archive. Inside the ZIP was a malicious Windows shortcut (LNK) file.
Upon extraction and execution, this LNK file would trigger a fileless malware infection via PowerShell scripts deploying a sophisticated payload known as RoKRAT, a proven remote access trojan (RAT) already associated with past APT37 intrusions.
APT37’s use of Dropbox as the command-and-control (C2) channel represents a continued evolution of “Living off Trusted Sites” (LoTS) attack methodology.
This approach mirrors “Living off the Land” techniques but abuses legitimate, globally trusted platforms such as Dropbox, pCloud, Yandex, OneDrive, and Google Drive to manage C2 communication and data exfiltration.

In these 2025 campaigns, Dropbox handled the upload, download, and deletion of payloads, while access tokens tied to Russian Yandex accounts helped the operators obscure attribution.
Technical analysis revealed that the LNK file, masquerading as an innocuous document (e.g., “To North Korean Soldiers Deployed to the Russian Battlefield.hwp”), executed hidden PowerShell commands designed to evade endpoint defenses.
The embedded commands launched decoy documents to distract the victim while simultaneously executing batched scripts in the background.
These scripts loaded multi-stage files in the %Temp% directory, using XOR encoding and fileless injection techniques to decrypt and execute RoKRAT malware directly in memory, thereby minimizing forensic traces.
Operation “ToyBox Story”
RoKRAT, the final payload, immediately harvested comprehensive system information, including OS version, device identifiers, manufacturer details, BIOS version, user names, and execution paths.

It proceeded to exfiltrate this data, along with live screenshots, via encrypted channels back to the Dropbox C2 infrastructure.
Notably, the malware’s encryption routines combined XOR obfuscation with AES-CBC-128, and the AES keys themselves were RSA-protected for additional complexity.
The spear phishing operation was broad in scope, with multiple observed variants. In one, attackers disguised the ZIP archive as an event poster; in another, they used content themes referencing sensitive North Korean troop deployments in Russia.
All cases employed the same RoKRAT backdoor, as confirmed by static and behavioral malware similarity analyses using tooling such as Capa and MITRE ATT&CK mapping.
GSC’s investigation traced threat infrastructure to several Yandex and Gmail accounts, some of which appeared on LinkedIn, though attribution remains under review.
APT37 continues to refine its tactics to evade EDR and AV tools, leaning heavily on fileless malware execution and cloud-based C2 to frustrate traditional enterprise detection methods.
Mitigation recommendations stress the necessity of real-time endpoint monitoring, anomaly-based threat hunting, and caution when handling unsolicited ZIP or LNK files especially those distributed via cloud storage links.
GSC’s Genian EDR demonstrated efficacy in detecting and isolating these threats, providing actionable forensics such as parent-child process trees and PowerShell command-line traces essential for incident response.
Indicators of Compromise (IOC)
| Type | Details |
|---|---|
| MD5 | 81c08366ea7fc0f933f368b120104384, 723f80d1843315717bc56e9e58e89be5, 7822e53536c1cf86c3e44e31e77bd088, 324688238c42d7190a2b50303cbc6a3c, a635bd019674b25038cd8f02e15eebd2, beeaca6a34fb05e73a6d8b7d2b8c2ee3, d5d48f044ff16ef6a4d5bde060ed5cee, d77c8449f1efc4bfb9ebff496442bbbc, 2f431c4e65af9908d2182c6a093bf262, 7cc8ce5374ff9eacd38491b75cbedf89, 8f339a09f0d0202cfaffbd38469490ec, 46ca088d5c052738d42bbd6231cc0ed5 |
| C2 IPs | 89.147.101[.]65, 89.147.101[.]71, 37.120.210[.]2 |
| E-mails | rolf.gehrung@yandex.com, ekta.sahasi@yandex.com, gursimran.bindra@yandex.com, sneha.geethakrishnan@yandex.com, tanessha.samuel@gmail.com, tianling0315@gmail.com, w.sarah0808@gmail.com, softpower21cs@gmail.com, sandozmessi@gmail.com, tiger.man.1999@mail.ru, navermail_noreply@mail.ru |
| Cloud C2 | api.pcloud[.]com, cloud-api.yandex[.]net, api.dropboxapi[.]com |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates