APT37 aka ScarCruft or RedEyes – Active IOCs

2024-12-09 Rewterz

https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37593

Thumbnail for APT37 aka ScarCruft or RedEyes – Active IOCs

Rewterz describes active APT37, ScarCruft, or RedEyes indicators tied to North Korean espionage activity, with recent reporting that the group expanded from CHM malware disguised as a Korean financial-company security email to RokRAT delivery through LNK files. The LNK files run PowerShell commands that create and execute scripts from a temporary folder, leading to RokRAT activity focused on additional payload execution and data exfiltration. RokRAT collects machine information before its main RAT loop and uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for command and control, making traffic harder to distinguish from legitimate cloud use. The advisory lists active IOCs, including uploader77j.disk.yandex.net and multiple hashes, for blocking and environment hunting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2fa8f5f95577db335e649d5361c845b0 2024-12-09 2024-12-09
HASH d9e3eba6067eec0aa32214b2a9811f4… 2024-12-09 2024-12-09
HASH c8bb4f1ebeafd00cc6b73e2cf265c18… 2024-12-09 2024-12-09
HASH 2500050253ecc95279b319bc469031d… 2024-12-09 2024-12-09
HASH ed825fe83c096ca29754c6b4e7e98384 2024-12-09 2024-12-09
HASH 5aacff1d13e872d1707c6d86646c886… 2024-12-09 2024-12-09
DOMAIN uploader77j.disk.yandex.net 2024-12-09 2024-12-09

Related Actors

Related Reports

« Back