APT-C-28(ScarCruft)利用MiradorShell发起网络攻击的安全预警
2026-02-06 • Qihoo360 • Security Warning: APT-C-28 (ScarCruft) Uses MiradorShell to Launch Cyberattacks •
APT-C-28, also tracked as ScarCruft or Konni, is reported targeting cryptocurrency and Web3 job or investment contexts with spear-phishing ZIP archives containing LNK files disguised as PDFs. The LNK launches obfuscated CMD, PowerShell, and dynamically compiled C# code to decrypt an embedded payload, collect host and file information, and avoid second-stage execution on apparent Google Compute Engine sandbox hosts. Victims that pass the checks receive AutoIt3.exe and an AU3 script from techcross-wne[.]com paths, producing the MiradorShell v2.0 reverse backdoor. MiradorShell connects to 65.21.182[.]178:443, supports shell access, file upload and download, directory listing, deletion, remote execution, scheduled-task persistence, and hardware-derived victim fingerprinting. The campaign matters because it combines Web3-themed social engineering, likely compromised Korean infrastructure, and a full-featured AutoIt backdoor for post-compromise control.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e4e7351cf3fc80e6f65c2226d1cafdb2 | 2026-02-06 | 2026-02-06 |
| HASH | f9945ddbfcb05ee49ba21d49e8087a18 | 2026-02-06 | 2026-02-06 |
| HASH | 4692034cd157c417c3868b5033d0e0d7 | 2026-02-06 | 2026-02-06 |
| HASH | ca1237bd33f61f77990d76a3df130ef5 | 2026-02-06 | 2026-02-06 |
| URL | https://techcross-wne.com/inclu… | 2026-02-06 | 2026-02-06 |
| URL | https://techcross-wne.com/inclu… | 2026-02-06 | 2026-02-06 |
| URL | https://techcross-wne.com/inclu… | 2026-02-06 | 2026-02-06 |
| DOMAIN | techcross-wne.com | 2026-02-06 | 2026-02-06 |
| IPv4 | 65.21.182.178 | 2026-02-06 | 2026-02-06 |