APT-C-28(ScarCruft)组织针对韩国部署Chinotto组件的活动分析

2023-12-01 Qihoo360 Analysis of the activities of APT-C-28 (ScarCruft) targeting the deployment of Chinotto components in South Korea

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247494166&idx=1&sn=c88fd9344d0a8b9597260d5d80dc7fce&chksm=f9c1d91fceb6500915a0e9cc5ecdf12d4202892a0b653e348a91f9769c583bdb33a212d22c16&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-28(ScarCruft)组织针对韩国部署Chinotto组件的活动分析

360 Threat Intelligence Center analyzed APT-C-28, also known as ScarCruft, activity targeting South Korea with Chinotto components. The excerpt shows LNK based delivery commands that extract Korean-language decoy documents and batch scripts from oversized shortcut files, including a seminar-themed PDF and a survey spreadsheet. The report says the group used phishing pages to collect victims' personal information, configured persistence on each execution, and varied remote connections loaded at startup. 360 assessed the memory-loaded Chinotto Trojan as feature rich and likely only partly disclosed based on the observed command set.

Indicators of Compromise

Type Value First Seen Last Seen
HASH fa03b0248a109a86eaddba108ebfcb14 2023-08-30 2023-12-01
HASH 16a34b0e194b3f825a19db5363df4cca 2023-08-30 2023-12-01

Related Actors

Related Reports

« Back