링크 파일(*.lnk)을 통해 유포되는 RokRAT 악성코드 : RedEyes(ScarCruft)
2023-04-21 • Ahnlab • RokRAT malware distributed through link files (*.lnk): RedEyes (ScarCruft) •
AhnLab reported that RedEyes, also known as APT37 or ScarCruft, was distributing RokRAT through malicious LNK files after earlier CHM-themed activity against domestic financial-company security mail. The LNK files contained PowerShell commands that extracted and opened a decoy PDF while dropping and executing a BAT script from the user's temp directory. The final PowerShell stage downloaded encoded data from OneDrive share URLs, decoded it, and injected RokRAT into a PowerShell process. RokRAT collected user information and could download additional malware, then used cloud services such as pCloud and Yandex for exfiltration while disguising its User-Agent as Googlebot.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-07-04 |
| URL | https://1drv.ms/i/s!AhXEXLJSNMP… | 2023-04-21 | 2023-07-04 |
| URL | https://1drv.ms/u/s!Au2my1xh6t8… | 2023-04-21 | 2023-06-06 |
| URL | https://api.onedrive.com/v1.0/s… | 2023-04-21 | 2023-06-06 |
| HASH | aa8ba9a029fa98b868be66b7d46e927b | 2023-04-21 | 2023-05-23 |
| HASH | 0f5eeb23d701a2b342fc15aa90d97ae0 | 2023-04-21 | 2023-05-23 |
| HASH | 657fd7317ccde5a0e0c182a626951a9f | 2023-04-21 | 2023-05-23 |
| HASH | be32725e676d49eaa11ff51c61f18907 | 2023-04-21 | 2023-05-23 |
| HASH | 461ce7d6c6062d1ae33895d1f44d98fb | 2023-04-21 | 2023-04-28 |
| HASH | 8fef5eb77e0a9ef2f97591d4d150a363 | 2023-04-21 | 2023-04-28 |