logo

APT37__2022__Internet_Explorer_0-day_exploited_by_North_Korean_actor_APT37.pdf

ID: d4c9dc7b-f137-4354-80be-e46713f411d4

STIX ID: report--d4c9dc7b-f137-4354-80be-e46713f411d4

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2022-12-14

Last Modified Date: 2022-12-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Google TAG describes an Internet Explorer JScript engine zero-day (CVE-2022-41128) actively exploited by North Korea–linked APT37 to deliver post-exploitation implants via malicious Microsoft Office documents that load remote RTF templates; the blog provides exploit analysis, delivery/behavior details (JIT type confusion, custom shellcode, cookie checks, cache clearing), and indicators including file hashes and C2 domains.