将目光对准高校——ScarCruft组织的新活动

2023-09-25 Sangfor Focus on colleges and universities – new campaign organized by ScarCruft

https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&mid=2247520758&idx=1&sn=7b0a96839a281ada20aee3f8c912be6b&chksm=ce461ae6f93193f0544c847defbd9855eb799ae9399744cf1d0018b0a6ba060cc866ec34a111&scene=178&cur_album_id=2867627575890837505#rd

Thumbnail for 将目光对准高校——ScarCruft组织的新活动

Sangfor attributes a university-focused campaign to ScarCruft/APT37 after observing the group’s familiar oversized LNK delivery, cloud-storage staging, and RokRAT payload. The lure was a ZIP file posing as Korea National Intelligence Society conference material; its PDF-looking LNK extracted a decoy PDF and batch script, pulled an encrypted payload from OneDrive, and decrypted shellcode that launched RokRAT. The malware used pCloud, Yandex, and Dropbox for command and control, matching ScarCruft’s pattern of blending malicious traffic into legitimate cloud services. Account artifacts tied the activity to Korean-language phishing emails sent to a North Korea research email address, including seminar and private-video lures.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 615673e320aa458e64d6430648ef17e… 2023-09-25 2023-09-25
HASH f72302b350af23070051ea3ac5ac42c9 2023-09-25 2023-09-25
HASH eaa5aa78668cfe6e6194fce6f2358ca8 2023-09-25 2023-09-25
HASH 1277e7fe0d2c9fab9ec6ba805485bd9b 2023-09-25 2023-09-25
HASH 558818f196b534ec263c6903d1599c3… 2023-09-25 2023-09-25
HASH f676a2d123e82280bad7529265d40fee 2023-09-25 2023-09-25
HASH ccffb9358fe57c15eaf07a984866fac… 2023-09-25 2023-09-25
HASH 2cafced7bd983a213938f906b185ffff 2023-09-25 2023-09-25
URL https://1drv.ms/u/s!AqoPnsoYBfB… 2023-09-25 2023-09-25
URL https://api.onedrive.com/v1.0/s… 2023-09-25 2023-09-25
URL https://1drv.ms/u/s!An8dLxzByH-… 2023-09-25 2023-09-25
URL https://api.onedrive.com/v1.0/s… 2023-09-25 2023-09-25
URL https://www.asiapress.org/korea… 2023-09-25 2023-09-25
URL https://api.onedrive.com/v1.0/s… 2023-09-25 2023-09-25
URL https://1drv.ms/u/s!AnUWfuEX4Ws… 2023-09-25 2023-09-25

Related Actors

Related Reports

« Back