Adversary Intelligence — 2026-05-15

North Korean APT37 Poses as Police and Defense Officials in Spear Phishing Campaign Targeting South Korean Security Figures

BLUFAPT37's multi-year account continuity and recycled C2 infrastructure point to an entrenched targeting program that very likely will produce another spear phishing campaign against South Korean security personnel by end of 2026.

Genians, a South Korean cybersecurity firm, reported on May 11 that APT37 targeted South Korean defense, national security, and North Korea-affairs personnel with spear-phishing emails that impersonated police investigators, defense officials, and North Korea research groups. The infection chain proceeded from ZIP-archived LNK files through environment variable-obfuscated batch scripts to a compiled Python backdoor disguised with a .cat extension, using C2 infrastructure that included Cafe24 senders and France-registered domains also identified in a prior APT37 deepfake campaign. Genians dated the campaign's most recent activity to the morning of April 17 from a malicious file's final save timestamp, and linked the actor account "Lailey" to 2022 operations impersonating the National Unification Advisory Council and the U.N. human rights office in Seoul.

Analysis
APT37's reuse of the "Lailey" actor account across campaigns from 2022 through April 2026, alongside overlapping C2 infrastructure shared with last year's deepfake military ID campaign, establishes a persistent operational cadence with no sign of disruption. Very likely, APT37 or another North Korean state-sponsored actor will conduct at least one additional spear phishing campaign targeting South Korean security and defense personnel by end of 2026. North Korea has concurrently restructured both the Ministry of State Security and the Reconnaissance General Bureau into agencies whose names explicitly foreground intelligence functions, signaling an institutional mandate to expand external collection and offensive cyber operations. The most recent malicious file carries an April 17 timestamp, placing active campaign work within the past month, and the group's pattern of rotating lure personas while preserving core infrastructure argues against a near-term operational stand-down. High confidence rests on the convergence of multi-year account continuity, shared IP addresses documented across separately disclosed campaigns, and a consistent obfuscation methodology that Genians traced independently.
2 sources
  1. North Korean hackers pose as police in spear phishing attacks - UPI
  2. North Korean hackers pose as police in spear phishing attacks - Occasional Digest

View in full brief →

UNCLASSIFIED // OPEN SOURCE