APT37 aka ScarCruft or RedEyes – Active IOCs

2024-11-14 Rewterz

https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37243

Thumbnail for APT37 aka ScarCruft or RedEyes – Active IOCs

APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group active since at least 2012, with primary targeting in South Korea and operations also reported in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and the Middle East. The advisory highlights recent RedEyes activity distributing RokRAT through LNK files after earlier CHM lures impersonated Korean financial security email. RokRAT collects host data, runs additional payloads, exfiltrates information, and uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for C2 to blend with legitimate traffic. The source provides active hash IOCs for hunting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bb83597cdf057db754def79d3f94b6c… 2024-11-14 2025-01-07
HASH 5b44285747891464c496aa477e450f10 2024-11-14 2025-01-07
HASH 73417ded382af2e0f3fca04d8d07679… 2024-11-14 2025-01-07
HASH a205d5bdfcd237462abaf6b9d3576c4a 2024-11-14 2024-11-14
HASH 13cc69320ed1e1422d13c3799998050… 2024-11-14 2024-11-14
HASH 49f1d203436240933ee20d7b16324c0… 2024-11-14 2024-11-14
HASH 198ee2c64c7584acb2403c0ce4c152b… 2024-11-14 2024-11-14
HASH ed691e1e20160346094c08d2cebf0f32 2024-11-14 2024-11-14
HASH 0ea29853d7300b8dbd4ddea9923ad79… 2024-11-14 2024-11-14

Related Actors

Related Reports

« Back