APT37针对韩国外交部下发RokRAT的窃密活动分析
2023-04-28 • 网络安全研究宅基地 • Analysis of APT37's secret theft activities against RokRAT issued by the Ministry of Foreign Affairs of South Korea •
DBAPPSecurity’s Lieying Lab analyzed an APT37, also known as Group123/RedEyes/ScarCruft, espionage campaign using RokRAT against South Korean foreign-affairs targets. The source says the attackers delivered an ISO containing two heavily padded LNK files that dropped HWP decoys and BAT files into the temp directory, then used PowerShell to download and decrypt the next-stage payload in memory. The final payload is RokRAT, which communicates with legitimate cloud services including pCloud, Dropbox, and Yandex to receive commands, upload selected files, execute Windows commands, and update cloud-service tokens. The report notes the 2023 infection chain added encrypted malicious commands ahead of earlier execution stages to hinder static detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2023-04-28 | 2023-04-28 | |
| HASH | 2cd04d9e11c6e458ec16db1ab810d625 | 2023-04-27 | 2023-04-28 |