Freenki is a Windows downloader and reconnaissance malware family attributed to APT37, also known as Reaper or Group 123. It collects host information, including MAC addresses, usernames, computer names, operating-system component versions, process architecture, WMI system details, and running processes. It can capture screenshots and retrieve, decode, and execute subsequent payloads through HTTP-based command-and-control communications. Some samples also contain browser credential-stealing code shared with ROKRAT.
Freenki requires specific command-line arguments to activate functionality and supports persistence through Windows startup registry entries. In the FreeMilk infection chain, the companion loader PoohMilk also established persistence for Freenki. The malware obfuscates strings and downloaded payloads, while its delivery chain has used encoded PowerShell and executable payloads disguised as images.
The May 2017 FreeMilk spear-phishing campaign delivered Freenki through customized malicious Office documents exploiting CVE-2017-0199. Attackers hijacked legitimate email conversations and used compromised accounts to contact selected recipients. Identified targets included a Middle Eastern bank, European trademark and intellectual-property service firms, an international sporting organization, and individuals with ties to Northeast Asia. Freenki was also deployed in an August 2016 watering-hole attack exploiting CVE-2016-0189 on a compromised anti-government media website operated by defectors in the United Kingdom.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers exploited CVE-2017-0199 in order to download and execute a malicious HTA document inside of Microsoft Office.
In August 2016, visitors to an anti-government media website operated by defectors in United Kingdom were targeted by watering hole attack with CVE-2016-0189 Microsoft Internet Explorer exploit. The exploit code attempted to deliver Freenki as payload malware. | The extracted PE payloads are what we label as PoohMilk and Freenki.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Freenki is used to gather information about the infected system and to download a subsequent stage payload.
APT37's Freenki malware lists running processes using the Microsoft Windows API.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
In August 2016, visitors to an anti-government media website operated by defectors in United Kingdom were targeted by watering hole attack with CVE-2016-0189 Microsoft Internet Explorer exploit. The exploit code attempted to deliver Freenki as payload malware.
The campaign started, unsurprisingly, with a malicious HWP document... This malicious document drops and executes a new version of ROKRAT.
Our research showed that the spear phishing emails came from multiple compromised email accounts tied to a legitimate domain in North East Asia. We believe that the threat actor hijacked an existing, legitimate in-progress conversation and posed as the legitimate senders to send malicious spear phishing emails to the recipients.
Then using the Windows API ShellExecuteW() and a hard-coded argument ‘abai’, the malware executes the decoded payload.
The C2 server responds with a Base64 encoded PowerShell script which in turn downloads two fake image files that contain embedded PE binaries and a JavaScript file which extracts the embedded PE binaries onto the victim host.
After a successful exploitation, it sets persistence in the registry with the appropriate command line argument to execute the second stage payload... HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ key name: runsample key value: "[CURRENT_EXECUTION_PATH] help"
After a successful exploitation, it sets persistence in the registry with the appropriate command line argument to execute the second stage payload... HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ key name: runsample key value: "[CURRENT_EXECUTION_PATH] help"
The first thing Freenki does is collect the host’s MAC address... Collects all Ethernet MAC addresses
0x31 = This identifier is used to send host information. Below are the details collected. Username ComputerName
The malware loops over sending this initial request until the C2 responds with a HTTP OK (200) status... all request are made with a HTTP POST method... the author uses the Windows API InternetOpenUrl(), therefore the secondary C2 address comes appended with either HTTP, HTTPS or FTP.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by APT37 that can enumerate running processes via Windows API calls.
APT37-attributed malware family used as a comparison point for developer-environment artifacts and TTPs (PowerShell-based delivery, compromised websites, JPG-delivered payloads, Windows-update-like naming for persistence).
Reconnaissance and downloading malware used by Group 123 in the FreeMilk campaign against non-Korean financial institutions, with earlier use documented in 2016. It collects system information through WMI, enumerates processes, supports registry-based persistence and downloads another executable. Strings and downloaded payloads use arithmetic and XOR obfuscation. A 2016 sample contains browser credential-stealing code later reused in ROKRAT, including extraction from browser databases and Microsoft Vault.
A downloader used in the FreeMilk campaign. The report states that the new ROKRAT version shares code with Freenki, indicating tooling overlap.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.