APT37针对韩国外交部下发RokRAT - 安恒威胁情报中心

2023-04-27 安恒信息 APT37 issues RokRAT targeting the Ministry of Foreign Affairs of South Korea - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2023/04/27/apt37-rokrat/

Thumbnail for APT37针对韩国外交部下发RokRAT - 安恒威胁情报中心

DBAPPSecurity reported APT37 activity against South Korea’s foreign-affairs sector using an ISO image that contained two large padded LNK files. When opened, the LNKs dropped HWP decoys and BAT scripts, then PowerShell downloaded and decrypted the next stage from OneDrive before loading RokRAT. The RokRAT sample used legitimate cloud services, especially pCloud, for command retrieval and supported host reconnaissance, file and process listing, payload download and execution, Windows command execution, and cloud-token updates. The report links the second-stage PowerShell to earlier APT37 tradecraft and notes added encryption in the infection chain to hinder static detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 657fd7317ccde5a0e0c182a626951a9f 2023-04-21 2023-05-23
HASH be32725e676d49eaa11ff51c61f18907 2023-04-21 2023-05-23
HASH 2cd04d9e11c6e458ec16db1ab810d625 2023-04-27 2023-04-28
HASH 461ce7d6c6062d1ae33895d1f44d98fb 2023-04-21 2023-04-28
HASH 979ae1db39fbf32a0f5c5ba581b648f0 2023-04-27 2023-04-27

Related Actors

Related Reports

« Back