APT-C-28(ScarCruft)组织利用无文件方式投递RokRat的攻击活动分析
2025-02-19 • Qihoo360 • Analysis of APT-C-28 (ScarCruft) attack activity delivering RokRAT filelessly •
APT-C-28 (ScarCruft), also known as APT37, Reaper, and Group123, targeted South Korean government and enterprise personnel with phishing archives containing malicious LNK files. The LNK files used PowerShell to extract decoy documents, malicious BAT and PowerShell scripts, and encrypted RokRat Shellcode, which was decrypted with XOR and executed in memory. The decrypted payload produced a RokRat PE compiled in October 2024, with core capabilities consistent with earlier RokRat versions but changes in delivery path and operational strategy. The campaign embedded the encrypted payload directly in the LNK instead of retrieving it from cloud services, likely reflecting adaptation after malicious cloud links were rapidly disabled. RokRat artifacts included a Googlebot-like User-Agent and the string "--wwjaughalvncjwiajs--", with commands for screenshots, process collection, file enumeration, payload retrieval, execution, and cleanup.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 144928fc87e1d50f5ed162bb1651ab24 | 2024-11-01 | 2025-06-27 |
| HASH | 936888d84b33f152d39ec539f5ce71aa | 2025-02-19 | 2025-02-19 |
| HASH | ee7e3e39dd951f352c669f64bd8ec1b5 | 2025-02-19 | 2025-02-19 |
| HASH | 0253b33cfb3deb6a1d4bb197895c4530 | 2025-02-19 | 2025-02-19 |
| HASH | 5adfa76b72236bf017f7968fd012e968 | 2025-01-21 | 2025-02-19 |
| HASH | f3c087a0be0687afd78829cab2d3bc2b | 2024-11-01 | 2025-02-19 |
| HASH | 3323777ca4ac2dc2c39f5c55c0c54e3c | 2024-11-01 | 2025-02-19 |
| HASH | 89c0d2cc1e71b17449eec454161d60da | 2024-11-01 | 2025-02-19 |
| HASH | 0af3b744c9d5deeb1697ce2a3565624b | 2024-04-23 | 2025-02-19 |