APT-C-28(ScarCruft)组织针对韩国部署Chinotto组件的活动分析
2023-12-01 • Qihoo360 • Analysis of the activities of APT-C-28 (ScarCruft) targeting the deployment of Chinotto components in South Korea •
360 Threat Intelligence Center analyzed APT-C-28, also known as ScarCruft, activity targeting South Korea with Chinotto components. The excerpt shows LNK based delivery commands that extract Korean-language decoy documents and batch scripts from oversized shortcut files, including a seminar-themed PDF and a survey spreadsheet. The report says the group used phishing pages to collect victims' personal information, configured persistence on each execution, and varied remote connections loaded at startup. 360 assessed the memory-loaded Chinotto Trojan as feature rich and likely only partly disclosed based on the observed command set.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | fa03b0248a109a86eaddba108ebfcb14 | 2023-08-30 | 2023-12-01 |
| HASH | 16a34b0e194b3f825a19db5363df4cca | 2023-08-30 | 2023-12-01 |