APT-C-28(ScarCruft)组织利用无文件方式投递RokRat的攻击活动分析

2025-02-19 Qihoo360 Analysis of APT-C-28 (ScarCruft) attack activity delivering RokRAT filelessly

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247505583&idx=1&sn=8ed8a00690db7f06260546c6a5142380

Thumbnail for APT-C-28(ScarCruft)组织利用无文件方式投递RokRat的攻击活动分析

APT-C-28 (ScarCruft), also known as APT37, Reaper, and Group123, targeted South Korean government and enterprise personnel with phishing archives containing malicious LNK files. The LNK files used PowerShell to extract decoy documents, malicious BAT and PowerShell scripts, and encrypted RokRat Shellcode, which was decrypted with XOR and executed in memory. The decrypted payload produced a RokRat PE compiled in October 2024, with core capabilities consistent with earlier RokRat versions but changes in delivery path and operational strategy. The campaign embedded the encrypted payload directly in the LNK instead of retrieving it from cloud services, likely reflecting adaptation after malicious cloud links were rapidly disabled. RokRat artifacts included a Googlebot-like User-Agent and the string "--wwjaughalvncjwiajs--", with commands for screenshots, process collection, file enumeration, payload retrieval, execution, and cleanup.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 144928fc87e1d50f5ed162bb1651ab24 2024-11-01 2025-06-27
HASH 936888d84b33f152d39ec539f5ce71aa 2025-02-19 2025-02-19
HASH ee7e3e39dd951f352c669f64bd8ec1b5 2025-02-19 2025-02-19
HASH 0253b33cfb3deb6a1d4bb197895c4530 2025-02-19 2025-02-19
HASH 5adfa76b72236bf017f7968fd012e968 2025-01-21 2025-02-19
HASH f3c087a0be0687afd78829cab2d3bc2b 2024-11-01 2025-02-19
HASH 3323777ca4ac2dc2c39f5c55c0c54e3c 2024-11-01 2025-02-19
HASH 89c0d2cc1e71b17449eec454161d60da 2024-11-01 2025-02-19
HASH 0af3b744c9d5deeb1697ce2a3565624b 2024-04-23 2025-02-19

Related Actors

Related Reports

« Back