APT37 aka ScarCruft or RedEyes – Active IOCs
2024-11-14 • Rewterz •
https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37243
APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group active since at least 2012, with primary targeting in South Korea and operations also reported in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and the Middle East. The advisory highlights recent RedEyes activity distributing RokRAT through LNK files after earlier CHM lures impersonated Korean financial security email. RokRAT collects host data, runs additional payloads, exfiltrates information, and uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for C2 to blend with legitimate traffic. The source provides active hash IOCs for hunting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bb83597cdf057db754def79d3f94b6c… | 2024-11-14 | 2025-01-07 |
| HASH | 5b44285747891464c496aa477e450f10 | 2024-11-14 | 2025-01-07 |
| HASH | 73417ded382af2e0f3fca04d8d07679… | 2024-11-14 | 2025-01-07 |
| HASH | a205d5bdfcd237462abaf6b9d3576c4a | 2024-11-14 | 2024-11-14 |
| HASH | 13cc69320ed1e1422d13c3799998050… | 2024-11-14 | 2024-11-14 |
| HASH | 49f1d203436240933ee20d7b16324c0… | 2024-11-14 | 2024-11-14 |
| HASH | 198ee2c64c7584acb2403c0ce4c152b… | 2024-11-14 | 2024-11-14 |
| HASH | ed691e1e20160346094c08d2cebf0f32 | 2024-11-14 | 2024-11-14 |
| HASH | 0ea29853d7300b8dbd4ddea9923ad79… | 2024-11-14 | 2024-11-14 |