APT37 aka ScarCruft or RedEyes – Active IOCs
2024-11-04 • Rewterz •
https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37073
APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group that mainly targets South Korea and has also operated against Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and Middle Eastern targets. The advisory links the group to RokRAT and Goldbackdoor, and notes a shift from HWP and Word delivery toward LNK files containing PowerShell commands. RokRAT collects machine data before running its RAT thread, uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for command and control, and supports additional payload execution and data exfiltration. Representative IOCs include 5f6682ad9da4590cba106e2f1a8cbe26 and dbd5d662cc53d4b91cf7da9979cdffd1b4f702323bb9ec4114371bc6f4f0d4a6.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 175.214.194.61 | 2024-11-04 | 2024-11-04 |
| IPv4 | 61.97.243.2 | 2024-11-04 | 2024-11-04 |
| IPv4 | 158.247.219.10 | 2024-11-04 | 2024-11-04 |
| IPv4 | 108.181.50.58 | 2024-11-04 | 2024-11-04 |
| HASH | 5f6682ad9da4590cba106e2f1a8cbe26 | 2024-03-04 | 2024-11-04 |
| HASH | dbd5d662cc53d4b91cf7da9979cdffd… | 2024-03-04 | 2024-11-04 |
| HASH | 7043c7c101532df47c832ce5270745d… | 2024-03-04 | 2024-11-04 |