Freenki is a Windows malware family associated with APT37 and the FreeMilk espionage campaign. It has been characterized as a downloader and host-information stealer used in targeted intrusions against selected victims, including organizations and individuals of intelligence interest. Reported targeting has included a Middle Eastern bank, European trademark and intellectual property firms, an international sporting organization, and persons connected to Korean Peninsula policy and North Korea-related issues. Freenki has also been linked to earlier watering-hole activity and shares code with later APT37-attributed tooling, including overlaps noted with ROKRAT and subsequent campaigns.
In observed FreeMilk infections, Freenki was delivered as a second-stage payload after exploitation of CVE-2017-0199 via spearphishing documents. A first-stage loader, PoohMilk, established persistence and launched Freenki. Separate reporting also links Freenki to watering-hole delivery in an earlier campaign exploiting CVE-2016-0189, and to broader APT37 tradecraft involving compromised websites and PowerShell-based retrieval of multiple payloads disguised as image files.
Freenki supports host reconnaissance and follow-on payload delivery. Documented functionality includes collecting system and user information, enumerating running processes through the Windows API, gathering WMI-derived host details, and capturing screenshots. It communicates with command-and-control infrastructure over HTTP POST-based tasking and can retrieve a secondary command-and-control address, download an additional payload, decode it, write it to temporary storage, and execute it with a hard-coded argument. Freenki also supports persistence through the Windows Run mechanism.
Operationally, Freenki has been tied to stealth-focused execution patterns, including requiring specific command-line arguments for meaningful execution in some samples. Code-sharing observations connect it to other APT37 malware families, particularly shared screenshot and downloader-related logic with ROKRAT and tooling used in the FreeMilk campaign. These overlaps, together with delivery patterns and infrastructure tradecraft, place Freenki within a broader cluster of North Korea-aligned espionage activity commonly attributed to APT37.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor leveraged the CVE-2017-0199 Microsoft Word Office/WordPad Remote Code Execution Vulnerability with carefully crafted decoy content customized for each target recipient... Upon successful exploitation, the malicious document delivered two malware payloads PoohMilk and Freenki. | The extracted PE payloads are what we label as PoohMilk and Freenki.
In August 2016, visitors to an anti-government media website operated by defectors in United Kingdom were targeted by watering hole attack with CVE-2016-0189 Microsoft Internet Explorer exploit. The exploit code attempted to deliver Freenki as payload malware. | The extracted PE payloads are what we label as PoohMilk and Freenki.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT37's Freenki malware lists running processes using the Microsoft Windows API.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
In August 2016, visitors to an anti-government media website operated by defectors in United Kingdom were targeted by watering hole attack with CVE-2016-0189 Microsoft Internet Explorer exploit. The exploit code attempted to deliver Freenki as payload malware.
The campaign started, unsurprisingly, with a malicious HWP document... This malicious document drops and executes a new version of ROKRAT.
Our research showed that the spear phishing emails came from multiple compromised email accounts tied to a legitimate domain in North East Asia. We believe that the threat actor hijacked an existing, legitimate in-progress conversation and posed as the legitimate senders to send malicious spear phishing emails to the recipients.
Then using the Windows API ShellExecuteW() and a hard-coded argument ‘abai’, the malware executes the decoded payload.
The C2 server responds with a Base64 encoded PowerShell script which in turn downloads two fake image files that contain embedded PE binaries and a JavaScript file which extracts the embedded PE binaries onto the victim host.
After a successful exploitation, it sets persistence in the registry with the appropriate command line argument to execute the second stage payload... HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ key name: runsample key value: "[CURRENT_EXECUTION_PATH] help"
After a successful exploitation, it sets persistence in the registry with the appropriate command line argument to execute the second stage payload... HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ key name: runsample key value: "[CURRENT_EXECUTION_PATH] help"
The first thing Freenki does is collect the host’s MAC address... Collects all Ethernet MAC addresses
0x31 = This identifier is used to send host information. Below are the details collected. Username ComputerName
The malware loops over sending this initial request until the C2 responds with a HTTP OK (200) status... all request are made with a HTTP POST method... the author uses the Windows API InternetOpenUrl(), therefore the secondary C2 address comes appended with either HTTP, HTTPS or FTP.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by APT37 that can enumerate running processes via Windows API calls.
APT37-attributed malware family used as a comparison point for developer-environment artifacts and TTPs (PowerShell-based delivery, compromised websites, JPG-delivered payloads, Windows-update-like naming for persistence).
A downloader used in the FreeMilk campaign. The report states that the new ROKRAT version shares code with Freenki, indicating tooling overlap.
Second-stage downloader that requires specific command-line arguments, establishes persistence, collects host information, sends victim profiling data to C2, captures screenshots, retrieves a secondary C2, downloads an additional payload, decodes it, and executes it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.