将目光对准高校——ScarCruft组织的新活动
2023-09-25 • Sangfor • Focus on colleges and universities – new campaign organized by ScarCruft •
Sangfor attributes a university-focused campaign to ScarCruft/APT37 after observing the group’s familiar oversized LNK delivery, cloud-storage staging, and RokRAT payload. The lure was a ZIP file posing as Korea National Intelligence Society conference material; its PDF-looking LNK extracted a decoy PDF and batch script, pulled an encrypted payload from OneDrive, and decrypted shellcode that launched RokRAT. The malware used pCloud, Yandex, and Dropbox for command and control, matching ScarCruft’s pattern of blending malicious traffic into legitimate cloud services. Account artifacts tied the activity to Korean-language phishing emails sent to a North Korea research email address, including seminar and private-video lures.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 615673e320aa458e64d6430648ef17e… | 2023-09-25 | 2023-09-25 |
| HASH | f72302b350af23070051ea3ac5ac42c9 | 2023-09-25 | 2023-09-25 |
| HASH | eaa5aa78668cfe6e6194fce6f2358ca8 | 2023-09-25 | 2023-09-25 |
| HASH | 1277e7fe0d2c9fab9ec6ba805485bd9b | 2023-09-25 | 2023-09-25 |
| HASH | 558818f196b534ec263c6903d1599c3… | 2023-09-25 | 2023-09-25 |
| HASH | f676a2d123e82280bad7529265d40fee | 2023-09-25 | 2023-09-25 |
| HASH | ccffb9358fe57c15eaf07a984866fac… | 2023-09-25 | 2023-09-25 |
| HASH | 2cafced7bd983a213938f906b185ffff | 2023-09-25 | 2023-09-25 |
| URL | https://1drv.ms/u/s!AqoPnsoYBfB… | 2023-09-25 | 2023-09-25 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-09-25 | 2023-09-25 |
| URL | https://1drv.ms/u/s!An8dLxzByH-… | 2023-09-25 | 2023-09-25 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-09-25 | 2023-09-25 |
| URL | https://www.asiapress.org/korea… | 2023-09-25 | 2023-09-25 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-09-25 | 2023-09-25 |
| URL | https://1drv.ms/u/s!AnUWfuEX4Ws… | 2023-09-25 | 2023-09-25 |