개인을 도청하는 RedEyes 그룹 (APT37)
2023-06-12 • Ahnlab • RedEyes group eavesdropping on individuals (APT37) •
AhnLab reports that RedEyes, also known as APT37, ScarCruft, and Reaper, targeted individuals such as North Korean defectors, human-rights activists, and university professors in May 2023. The attack chain began with spear-phishing that paired a password-protected benign document with a CHM file posing as the password file; opening the CHM launched MSHTA to retrieve scripts from attacker infrastructure and install a PowerShell backdoor with Run-key persistence. The group used a Golang Ably-based backdoor that fetched a Base64-encoded channel key from GitHub, exchanged UP/DOWN messages over Ably for command execution, and then used COM hijacking and fileless execution to deploy an information stealer. ASEC named the stealer FadeStealer and described screenshot capture, removable-media and smartphone data theft, keylogging, microphone eavesdropping, RAR-compressed exfiltration every 30 minutes, and C2 paths on 172.93.181[.]249.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1c1136c12d0535f4b90e32aa36070682 | 2023-06-12 | 2025-09-26 |
| HASH | 1352abf9de97a0faf8645547211c3be7 | 2023-06-12 | 2025-09-26 |
| HASH | 3277e0232ed6715f2bae526686232e06 | 2023-06-12 | 2025-09-26 |
| HASH | 59804449f5670b4b9b3b13efdb296abb | 2023-06-12 | 2025-09-26 |
| HASH | 3c475d80f5f6272234da821cc418a6f7 | 2023-06-12 | 2025-09-26 |
| IPv4 | 172.93.181.249 | 2023-06-12 | 2025-09-26 |
| HASH | f44bf949abead4af0966436168610bcc | 2023-06-12 | 2023-06-21 |