#Artemis
Incident/Operation
2025-12-21 • 작전명 아르테미스: HWP 기반 DLL 사이드 로딩 공격 분석
Artemis is an APT37 campaign identified in 2025 that targeted South Korean recipients by impersonating television writers arranging casting or interviews. The operators delivered HWP documents disguised as questionnaires or event guides, embedded malicious OLE objects, and relied on the recipient clicking a hyperlink to begin a multistage infection. The chain launched a legitimate process and then used DLL side-loading to execute a malicious payload in that process context, blending benign and malicious execution flows to evade signature-based detection and support reconnaissance and intrusion.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days