A covert operation orchestrated by North Korea's APT37 group has compromised numerous organizations across defense, law enforcement, and academic circles This article explores korea state intelligence. . Researchers at Genians Security Center have identified a sophisticated campaign dubbed the Vidar Campaign, which uses Python malware disguised as benign software and obfuscated commands to silently infiltrate networks.
The attack starts with spear-phishing emails designed to trick victims into clicking on links that download the malware. Screens from Spear-Phishing cases reveal the threat group, believed to operate under North Korea's state intelligence apparatus, has a history of using similar infrastructure. Researchers identified identical Command & Control (C2) IP addresses, overlapping code obfuscation techniques, and the continued use of Korean web hosting services like Cafe24 alongside French domains in recent attacks.
The repeated appearance of user account "Lailey" in decoy documents further connects this campaign to previous attempts targeting human rights organizations and unification groups. Indicators of Compromise (IOCs) Indicator Type Value Description C2 Domain kmot.co.kr Payload hosting and C2 communication C2 Domain choisy.fr Associated C2 infrastructure IP Address 51.158.21.1 Repeated APT37 infrastructure IP File Name settingenv.cat Disguised Python bytecode payload












