스테가노그래피 기법 사용한 한글(HWP) 악성코드 : RedEyes(ScarCruft)

2023-02-14 Ahnlab RedEyes ScarCruft HWP malware using steganography

https://asec.ahnlab.com/ko/47622/

Thumbnail for 스테가노그래피 기법 사용한 한글(HWP) 악성코드 : RedEyes(ScarCruft)

AhnLab attributed a January 2023 HWP attack to RedEyes/ScarCruft, also known as APT37, based on the use of steganographic payload delivery and persistence commands resembling earlier ScarCruft activity. The initial access vector abused the old Hangul EPS vulnerability CVE-2017-8291 in a document named “양식.hwp,” causing shellcode to download a JPEG that concealed an encoded PE payload. The decoded executable dropped and injected a new backdoor named M2RAT into explorer.exe, while Run-key persistence launched PowerShell and mshta against attacker-controlled HTML/HTA infrastructure. M2RAT provided remote control, keylogging, screen capture, process control, and document or audio exfiltration while using shared-memory sections and POST-body C2 to reduce host and network artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 93c66ee424daf4c5590e21182592672e 2023-02-14 2023-02-14
HASH 9083c1ff01ad8fabbcd8af1b63b77e66 2023-02-14 2023-02-14
HASH 7f5a72be826ea2fe5f11a16da0178e54 2023-02-14 2023-02-14
HASH 4488c709970833b5043c0b0ea2ec9fa9 2023-02-14 2023-02-14
HASH 8b666fc04af6de45c804d973583c76e0 2023-02-14 2023-02-14
HASH 7bab405fbc6af65680443ae95c30595d 2023-02-14 2023-02-14
DOMAIN wallup.net 2023-02-14 2023-02-14

Related Actors

Related Reports

« Back