스테가노그래피 기법 사용한 한글(HWP) 악성코드 : RedEyes(ScarCruft)
2023-02-14 • Ahnlab • RedEyes ScarCruft HWP malware using steganography •
AhnLab attributed a January 2023 HWP attack to RedEyes/ScarCruft, also known as APT37, based on the use of steganographic payload delivery and persistence commands resembling earlier ScarCruft activity. The initial access vector abused the old Hangul EPS vulnerability CVE-2017-8291 in a document named “양식.hwp,” causing shellcode to download a JPEG that concealed an encoded PE payload. The decoded executable dropped and injected a new backdoor named M2RAT into explorer.exe, while Run-key persistence launched PowerShell and mshta against attacker-controlled HTML/HTA infrastructure. M2RAT provided remote control, keylogging, screen capture, process control, and document or audio exfiltration while using shared-memory sections and POST-body C2 to reduce host and network artifacts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 93c66ee424daf4c5590e21182592672e | 2023-02-14 | 2023-02-14 |
| HASH | 9083c1ff01ad8fabbcd8af1b63b77e66 | 2023-02-14 | 2023-02-14 |
| HASH | 7f5a72be826ea2fe5f11a16da0178e54 | 2023-02-14 | 2023-02-14 |
| HASH | 4488c709970833b5043c0b0ea2ec9fa9 | 2023-02-14 | 2023-02-14 |
| HASH | 8b666fc04af6de45c804d973583c76e0 | 2023-02-14 | 2023-02-14 |
| HASH | 7bab405fbc6af65680443ae95c30595d | 2023-02-14 | 2023-02-14 |
| DOMAIN | wallup.net | 2023-02-14 | 2023-02-14 |