APT37 aka ScarCruft or RedEyes – Active IOCs

2024-11-04 Rewterz

https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37073

Thumbnail for APT37 aka ScarCruft or RedEyes – Active IOCs

APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group that mainly targets South Korea and has also operated against Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and Middle Eastern targets. The advisory links the group to RokRAT and Goldbackdoor, and notes a shift from HWP and Word delivery toward LNK files containing PowerShell commands. RokRAT collects machine data before running its RAT thread, uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for command and control, and supports additional payload execution and data exfiltration. Representative IOCs include 5f6682ad9da4590cba106e2f1a8cbe26 and dbd5d662cc53d4b91cf7da9979cdffd1b4f702323bb9ec4114371bc6f4f0d4a6.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 175.214.194.61 2024-11-04 2024-11-04
IPv4 61.97.243.2 2024-11-04 2024-11-04
IPv4 158.247.219.10 2024-11-04 2024-11-04
IPv4 108.181.50.58 2024-11-04 2024-11-04
HASH 5f6682ad9da4590cba106e2f1a8cbe26 2024-03-04 2024-11-04
HASH dbd5d662cc53d4b91cf7da9979cdffd… 2024-03-04 2024-11-04
HASH 7043c7c101532df47c832ce5270745d… 2024-03-04 2024-11-04

Related Actors

Related Reports

« Back