云中谍影:Group123组织近期攻击活动分析

2023-07-11 Qianxin Spies in the Cloud: Analysis of recent attack activities by Group123

https://ti.qianxin.com/blog/articles/Cloud-Spy-Analysis-of-Recent-Attack-Activities-by-Group123-CN/

Thumbnail for 云中谍影:Group123组织近期攻击活动分析

Group123, also tracked as ScarCruft/APT-Q-3 and linked by the source to North Korea, has recently increased attacks against South Korean targets using oversized LNK files disguised as legitimate documents. The campaign uses spear-phishing-style archives containing decoy PDF/HWP content about Korean defense, diplomacy, North Korea policy, or audio lures; double-clicking the LNK runs PowerShell, drops a date-named BAT file in %temp%, and retrieves follow-on payloads from OneDrive. The payload chain XOR-decrypts and reflectively injects RokRAT, a long-running Group123 remote-access trojan that can capture screenshots, log keystrokes, perform anti-VM checks, and use cloud services such as OneDrive, Box, Dropbox, and Yandex for C2. The report also notes large junk-filled LNK files and custom use of an EmbedExeLnk-style builder as evasion and delivery mechanisms.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fe5520783f715549cc3c4df9deaf89bf 2023-07-11 2024-03-27
HASH 5776368e1a8483d11f3ee1c383f193c4 2023-07-11 2023-07-11
HASH 71dbebb8a31ea3de0115851bb15fd2bc 2023-07-11 2023-07-11
HASH c14a66e1a039d2e51cb70adb609df872 2023-07-11 2023-07-11
HASH 44ba46dfff78bc62a3b2619d308ca40c 2023-07-11 2023-07-11
HASH 7504a626993179e5819246234ca6c4c9 2023-07-11 2023-07-11
HASH 1da701990560b8b0db2c4441145a3ee3 2023-07-11 2023-07-11
HASH 61f4946837d7cd1701eedb3c372121c6 2023-07-11 2023-07-11
HASH 484bcb44845946e444f05295cf19e98e 2023-07-11 2023-07-11
HASH 487769a19f032e981f33023b2cb7fe10 2023-07-11 2023-07-11
HASH 7095811df4cb1ee4135ce605af7f163f 2023-07-11 2023-07-11
HASH f93754e660802d7cc70924cceb4738ef 2023-07-11 2023-07-11
HASH 72b3765580c8c8588feccf06f98c090b 2023-07-11 2023-07-11
URL https://1drv.ms/i/s!AgK8WVCyy__… 2023-07-11 2023-07-11
URL https://1drv.ms/u/s!AtzyIIRGrnB… 2023-07-11 2023-07-11
URL http://vmi810830.contaboserver.… 2023-07-11 2023-07-11
URL https://api.onedrive.com/v1.0/s… 2023-07-11 2023-07-11
URL https://1drv.ms/i/s!AmDQ53DcLMU… 2023-07-11 2023-07-11
URL https://api.onedrive.com/v1.0/s… 2023-07-11 2023-07-11
URL https://api.onedrive.com/v1.0/s… 2023-07-11 2023-07-11
DOMAIN vmi810830.contaboserver.net 2023-07-11 2023-07-11
HASH 74e3d84492845067a0da6cfa00c064eb 2023-05-23 2023-07-11
HASH 02685c2ffc30c55667076cfb01033060 2023-05-18 2023-07-11
HASH 445e7fd6bb684420d6b8523fe0c55228 2023-05-18 2023-07-11

Related Actors

Related Reports

« Back