#ToyBoxStory

Incident/Operation

2025-05-12 • Analysis of APT37 Attack Case Disguised as a Think Tank for National Security Strategy in South Korea (Operation. ToyBox Story)

ToyBox Story is a March 2025 APT37 spear-phishing operation targeting South Korean activists and experts concerned with North Korea and national-security policy. Operators impersonated real specialists and a national-security think tank, reused genuine event themes, and linked victims to Dropbox archives containing malicious LNK files disguised as HWP material. Execution launched additional components associated with the campaign’s “toy” marker, while Dropbox also served command-and-control functions, extending APT37’s practice of abusing trusted cloud platforms to conceal fileless activity and evade conventional filtering.

Tagged Reports

« Back