APT37针对韩国外交部下发RokRAT的窃密活动分析

2023-04-28 网络安全研究宅基地 Analysis of APT37's secret theft activities against RokRAT issued by the Ministry of Foreign Affairs of South Korea

https://mp.weixin.qq.com/s/iCFz9vhYGxz0cd8_0-PhDQ

Thumbnail for APT37针对韩国外交部下发RokRAT的窃密活动分析

DBAPPSecurity’s Lieying Lab analyzed an APT37, also known as Group123/RedEyes/ScarCruft, espionage campaign using RokRAT against South Korean foreign-affairs targets. The source says the attackers delivered an ISO containing two heavily padded LNK files that dropped HWP decoys and BAT files into the temp directory, then used PowerShell to download and decrypt the next-stage payload in memory. The final payload is RokRAT, which communicates with legitimate cloud services including pCloud, Dropbox, and Yandex to receive commands, upload selected files, execute Windows commands, and update cloud-service tokens. The report notes the 2023 infection chain added encrypted malicious commands ahead of earlier execution stages to hinder static detection.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2023-04-28 2023-04-28
HASH 2cd04d9e11c6e458ec16db1ab810d625 2023-04-27 2023-04-28

Related Actors

Related Reports

« Back