North Korean threat actor APT37 targeted South Korean users through multiple intrusion chains that combined malicious documents with Internet Explorer engine exploitation. Google linked the group to CVE-2022-41128, a type confusion flaw in jscript9.dll that enabled arbitrary code execution after victims opened Office lures themed around the Itaewon tragedy; the documents fetched remote content that was rendered through Internet Explorer, validated infections with cookies, reported to command-and-control servers, and then downloaded follow-on payloads while clearing browser artifacts. Genian later reported a sustained 2023 campaign in which APT37 used HWP, HWPX, LNK, DOCX, and XLSX files, with embedded OLE objects in Korean document formats triggering connections to attacker-controlled infrastructure and reflecting techniques tied to the earlier Internet Explorer exploit activity.
AhnLab and South Korea’s NCSC also disclosed a separate APT37 operation exploiting CVE-2024-38178, another jscript9.dll type confusion vulnerability in the legacy Internet Explorer engine. In that campaign, attackers compromised a domestic advertising agency server and weaponized toast-style ad software that still depended on Internet Explorer, creating a zero-click infection path in which malicious ad content was automatically downloaded and rendered without user interaction. The resulting malware provided remote command execution and other post-compromise capabilities, underscoring APT37’s continued focus on South Korean targets and its repeated abuse of deprecated browser components and document-based lures to gain code execution.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
From around May 2023 through November 2023, Genian Security Center observed sustained APT37 activity targeting South Korean users with HWP and HWPX documents containing embedded OLE objects, alongside LNK, DOCX, and XLSX files. The embedded OLE content initiated connections to attacker-controlled servers, where exploit commands were then invoked.
Microsoft released a patch for CVE-2022-41128 on November 8, 2022. The vulnerability had been exploited by APT37 using malicious Office documents that fetched remote content rendered through Internet Explorer.
Microsoft assigned the identifier CVE-2022-41128 to the Internet Explorer JScript engine vulnerability on November 3, 2022. The flaw was a type confusion issue in jscript9.dll that could enable arbitrary code execution.
Google Threat Analysis Group reported the in-the-wild Internet Explorer zero-day CVE-2022-41128 to Microsoft on October 31, 2022. TAG assessed the exploitation activity against South Korean users as part of an APT37 campaign.
Multiple submitters from South Korea uploaded a malicious Office document tied to the campaign to VirusTotal on October 31, 2022. Google TAG linked the document to exploitation of the Internet Explorer zero-day CVE-2022-41128.
In late October 2022, malicious DOCX documents themed around the Itaewon incident were distributed in South Korea, including to a group chat with North Korea specialists. One lure impersonated an official document titled "Yongsan Itaewon accident response status."
Microsoft ended support for Internet Explorer in June 2022. Later reporting noted that attackers continued exploiting legacy applications that still embedded Internet Explorer components.
AhnLab ASEC and South Korea's National Cyber Security Center published a joint report titled "Operation Code on Toast by TA-RedAnt" detailing the zero-click exploitation of CVE-2024-38178. The report attributed the operation to the North Korean threat actor TA-RedAnt, also known as APT37.
Microsoft released a patch for CVE-2024-38178 in its August 13 security updates, based on U.S. local time. The vulnerability had been exploited in a zero-click campaign abusing software that still rendered advertising content with Internet Explorer components.
Microsoft assigned the identifier CVE-2024-38178 to the newly reported Internet Explorer vulnerability. Microsoft rated the flaw with a CVSS score of 7.5.
After discovering and analyzing a new Internet Explorer zero-day exploited by TA-RedAnt, AhnLab ASEC and South Korea's National Cyber Security Center immediately reported the issue to Microsoft. The flaw affected jscript9.dll and enabled malware installation through vulnerable ad software.
In the TA-RedAnt campaign later documented by AhnLab and NCSC, attackers first compromised a domestic advertising agency server used by a toast advertising program and inserted exploit code into ad-related scripts. The malicious content was then automatically downloaded and rendered by software still using the Internet Explorer engine, enabling zero-click exploitation.
The National Security Office of the Presidential Office distributed a press release warning about cyber threats abusing the Itaewon incident issue. The warning came in response to the malicious document activity tied to the earlier APT37 campaign.
During the Itaewon-themed malicious document incident, the Korea Internet & Security Agency activated a public-private cyber cooperation channel centered on its threat intelligence network. The associated command-and-control server was later blocked after analysis.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcegenians.co.kr
Open sourceblog.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.