APT37针对韩国外交部下发RokRAT - 安恒威胁情报中心
2023-04-27 • 安恒信息 • APT37 issues RokRAT targeting the Ministry of Foreign Affairs of South Korea - Anheng Threat Intelligence Center •
https://starmap.dbappsecurity.com.cn/blog/articles/2023/04/27/apt37-rokrat/
DBAPPSecurity reported APT37 activity against South Korea’s foreign-affairs sector using an ISO image that contained two large padded LNK files. When opened, the LNKs dropped HWP decoys and BAT scripts, then PowerShell downloaded and decrypted the next stage from OneDrive before loading RokRAT. The RokRAT sample used legitimate cloud services, especially pCloud, for command retrieval and supported host reconnaissance, file and process listing, payload download and execution, Windows command execution, and cloud-token updates. The report links the second-stage PowerShell to earlier APT37 tradecraft and notes added encryption in the infection chain to hinder static detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 657fd7317ccde5a0e0c182a626951a9f | 2023-04-21 | 2023-05-23 |
| HASH | be32725e676d49eaa11ff51c61f18907 | 2023-04-21 | 2023-05-23 |
| HASH | 2cd04d9e11c6e458ec16db1ab810d625 | 2023-04-27 | 2023-04-28 |
| HASH | 461ce7d6c6062d1ae33895d1f44d98fb | 2023-04-21 | 2023-04-28 |
| HASH | 979ae1db39fbf32a0f5c5ba581b648f0 | 2023-04-27 | 2023-04-27 |