APT-C-28(ScarCruft)组织针对能源方向投放Rokrat后门活动分析

2023-07-13 Qihoo360 Analysis of APT-C-28 (ScarCruft) organization's Rokrat backdoor activities targeting the energy direction

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247492864&idx=1&sn=0af3b744c9d5deeb1697ce2a3565624b&chksm=f9c1d609ceb65f1f62c856e57004fe90fe059d688a7a858b483208cfe832b3d5ab77d13f3f1e&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-28(ScarCruft)组织针对能源方向投放Rokrat后门活动分析

360’s threat research team reported APT-C-28/ScarCruft activity using an energy-sector lure about the Sharara-to-Mellitah oil pipeline to deliver the RokRAT backdoor. The attack used a large padded LNK file containing a decoy PDF and malicious BAT logic, then PowerShell pulled an encrypted RokRAT payload from OneDrive, decrypted it, and ran it in memory. The RokRAT sample collected host and user details, supported file transfer, command execution, screenshots, and keylogging, and used cloud storage APIs including pCloud, Yandex, and Dropbox for command and file exchange. The report notes continuity with earlier RokRAT behavior, including familiar file naming, code structure, and HTTP content-type patterns.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4fe698c235d03a271305db8ffdaa9e36 2023-07-13 2023-07-13
HASH 4d3464b23dd4fb141c8fcc4cbf541832 2023-07-13 2023-07-13
HASH 2c180bf7a1e6dbe84060c3b5aa53feb7 2023-07-13 2023-07-13
HASH 7b7c43ed1eb6a423bdcfd0484fe560c3 2023-07-13 2023-07-13
HASH 85e71578ad7fea3c15095b6185b14881 2023-05-23 2023-07-13
URL https://1drv.ms/u/s!AjQNLvEE_CU… 2023-05-01 2023-07-13
URL https://api.onedrive.com/v1.0/s… 2023-05-01 2023-07-13

Related Actors

Related Reports

« Back