링크 파일(*.lnk)을 통해 유포되는 RokRAT 악성코드 : RedEyes(ScarCruft)

2023-04-21 Ahnlab RokRAT malware distributed through link files (*.lnk): RedEyes (ScarCruft)

https://asec.ahnlab.com/ko/51628/

Thumbnail for 링크 파일(*.lnk)을 통해 유포되는 RokRAT 악성코드 : RedEyes(ScarCruft)

AhnLab reported that RedEyes, also known as APT37 or ScarCruft, was distributing RokRAT through malicious LNK files after earlier CHM-themed activity against domestic financial-company security mail. The LNK files contained PowerShell commands that extracted and opened a decoy PDF while dropping and executing a BAT script from the user's temp directory. The final PowerShell stage downloaded encoded data from OneDrive share URLs, decoded it, and injected RokRAT into a PowerShell process. RokRAT collected user information and could download additional malware, then used cloud services such as pCloud and Yandex for exfiltration while disguising its User-Agent as Googlebot.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-07-04
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-04-21 2023-07-04
URL https://1drv.ms/u/s!Au2my1xh6t8… 2023-04-21 2023-06-06
URL https://api.onedrive.com/v1.0/s… 2023-04-21 2023-06-06
HASH aa8ba9a029fa98b868be66b7d46e927b 2023-04-21 2023-05-23
HASH 0f5eeb23d701a2b342fc15aa90d97ae0 2023-04-21 2023-05-23
HASH 657fd7317ccde5a0e0c182a626951a9f 2023-04-21 2023-05-23
HASH be32725e676d49eaa11ff51c61f18907 2023-04-21 2023-05-23
HASH 461ce7d6c6062d1ae33895d1f44d98fb 2023-04-21 2023-04-28
HASH 8fef5eb77e0a9ef2f97591d4d150a363 2023-04-21 2023-04-28

Related Actors

Related Reports

« Back