RedEyes Group Wiretapping Individuals (APT37)

2023-06-21 Ahnlab

https://asec.ahnlab.com/en/54349/

Thumbnail for RedEyes Group Wiretapping Individuals (APT37)

ASEC attributed a May 2023 campaign to RedEyes/APT37, also known as ScarCruft/Reaper, targeting individuals such as North Korean defectors, human-rights activists, and university professors. The intrusion used spear-phishing attachments that paired a normal password-protected document with CHM malware disguised as a password file; executing the CHM launched MSHTA and a PowerShell backdoor with autorun persistence. Later stages used an Ably-based GoLang backdoor that retrieved its channel authentication key from GitHub, enabling command exchange, privilege escalation, exfiltration, and additional malware delivery. ASEC also observed a previously unknown infostealer with wiretapping features, underscoring RedEyes’ focus on monitoring specific individuals.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1c1136c12d0535f4b90e32aa36070682 2023-06-12 2025-09-26
HASH 1352abf9de97a0faf8645547211c3be7 2023-06-12 2025-09-26
HASH 3277e0232ed6715f2bae526686232e06 2023-06-12 2025-09-26
HASH 59804449f5670b4b9b3b13efdb296abb 2023-06-12 2025-09-26
HASH 3c475d80f5f6272234da821cc418a6f7 2023-06-12 2025-09-26
IPv4 172.93.181.249 2023-06-12 2025-09-26
HASH f44bf949abead4af0966436168610bcc 2023-06-12 2023-06-21

Related Actors

Related Reports

« Back