APT37__2022__Internet_Explorer_0-day_exploited_by_North_Korean_actor_APT37.pdf
ID: d4c9dc7b-f137-4354-80be-e46713f411d4
STIX ID: report--d4c9dc7b-f137-4354-80be-e46713f411d4
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2022-12-14
Last Modified Date: 2022-12-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Google TAG describes an Internet Explorer JScript engine zero-day (CVE-2022-41128) actively exploited by North Korea–linked APT37 to deliver post-exploitation implants via malicious Microsoft Office documents that load remote RTF templates; the blog provides exploit analysis, delivery/behavior details (JIT type confusion, custom shellcode, cookie checks, cache clearing), and indicators including file hashes and C2 domains.
