APT-C-28(ScarCruft)利用MiradorShell发起网络攻击的安全预警

2026-02-06 Qihoo360 Security Warning: APT-C-28 (ScarCruft) Uses MiradorShell to Launch Cyberattacks

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247507801&idx=1&sn=e169339f921fd11a2fef8dfe068e616c&poc_token=HItfiWmjwCP6DUilL4b_EXSlNu_FoMKECyYW0Sig

Thumbnail for APT-C-28(ScarCruft)利用MiradorShell发起网络攻击的安全预警

APT-C-28, also tracked as ScarCruft or Konni, is reported targeting cryptocurrency and Web3 job or investment contexts with spear-phishing ZIP archives containing LNK files disguised as PDFs. The LNK launches obfuscated CMD, PowerShell, and dynamically compiled C# code to decrypt an embedded payload, collect host and file information, and avoid second-stage execution on apparent Google Compute Engine sandbox hosts. Victims that pass the checks receive AutoIt3.exe and an AU3 script from techcross-wne[.]com paths, producing the MiradorShell v2.0 reverse backdoor. MiradorShell connects to 65.21.182[.]178:443, supports shell access, file upload and download, directory listing, deletion, remote execution, scheduled-task persistence, and hardware-derived victim fingerprinting. The campaign matters because it combines Web3-themed social engineering, likely compromised Korean infrastructure, and a full-featured AutoIt backdoor for post-compromise control.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e4e7351cf3fc80e6f65c2226d1cafdb2 2026-02-06 2026-02-06
HASH f9945ddbfcb05ee49ba21d49e8087a18 2026-02-06 2026-02-06
HASH 4692034cd157c417c3868b5033d0e0d7 2026-02-06 2026-02-06
HASH ca1237bd33f61f77990d76a3df130ef5 2026-02-06 2026-02-06
URL https://techcross-wne.com/inclu… 2026-02-06 2026-02-06
URL https://techcross-wne.com/inclu… 2026-02-06 2026-02-06
URL https://techcross-wne.com/inclu… 2026-02-06 2026-02-06
DOMAIN techcross-wne.com 2026-02-06 2026-02-06
IPv4 65.21.182.178 2026-02-06 2026-02-06

Related Actors

Related Reports

« Back