APT37 aka ScarCruft or RedEyes – Active IOCs
2024-12-09 • Rewterz •
https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37593
Rewterz describes active APT37, ScarCruft, or RedEyes indicators tied to North Korean espionage activity, with recent reporting that the group expanded from CHM malware disguised as a Korean financial-company security email to RokRAT delivery through LNK files. The LNK files run PowerShell commands that create and execute scripts from a temporary folder, leading to RokRAT activity focused on additional payload execution and data exfiltration. RokRAT collects machine information before its main RAT loop and uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for command and control, making traffic harder to distinguish from legitimate cloud use. The advisory lists active IOCs, including uploader77j.disk.yandex.net and multiple hashes, for blocking and environment hunting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2fa8f5f95577db335e649d5361c845b0 | 2024-12-09 | 2024-12-09 |
| HASH | d9e3eba6067eec0aa32214b2a9811f4… | 2024-12-09 | 2024-12-09 |
| HASH | c8bb4f1ebeafd00cc6b73e2cf265c18… | 2024-12-09 | 2024-12-09 |
| HASH | 2500050253ecc95279b319bc469031d… | 2024-12-09 | 2024-12-09 |
| HASH | ed825fe83c096ca29754c6b4e7e98384 | 2024-12-09 | 2024-12-09 |
| HASH | 5aacff1d13e872d1707c6d86646c886… | 2024-12-09 | 2024-12-09 |
| DOMAIN | uploader77j.disk.yandex.net | 2024-12-09 | 2024-12-09 |