후쿠시마 오염수 방류 내용을 이용한 CHM 악성코드 : RedEyes(ScarCruft)

2023-09-04 Ahnlab CHM malware using Fukushima contaminated water discharge: RedEyes (ScarCruft)

https://asec.ahnlab.com/ko/56654/

Thumbnail for 후쿠시마 오염수 방류 내용을 이용한 CHM 악성코드 : RedEyes(ScarCruft)

AhnLab reported renewed distribution of CHM malware believed to be associated with RedEyes/ScarCruft, using public concern over Fukushima contaminated-water discharge as the lure. Unlike earlier variants that launched mshta directly from the CHM help file, this sample registered a Run key command so the mshta chain would execute after reboot. The decoded PowerShell acted as a backdoor that contacted navercorp[.]ru paths for command retrieval and Base64-encoded result reporting. Documented commands covered file inventory and upload, directory compression and exfiltration, file download, scheduled-task registration, archive extraction, and file renaming, enabling follow-on payload delivery and information theft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 52f71fadf0ea5ffacd753e83a3d0af1a 2023-09-04 2023-09-08
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
DOMAIN navercorp.ru 2023-09-04 2023-09-08

Related Actors

Related Reports

« Back