RedEyes Group Wiretapping Individuals (APT37)
2023-06-21 • Ahnlab •
ASEC attributed a May 2023 campaign to RedEyes/APT37, also known as ScarCruft/Reaper, targeting individuals such as North Korean defectors, human-rights activists, and university professors. The intrusion used spear-phishing attachments that paired a normal password-protected document with CHM malware disguised as a password file; executing the CHM launched MSHTA and a PowerShell backdoor with autorun persistence. Later stages used an Ably-based GoLang backdoor that retrieved its channel authentication key from GitHub, enabling command exchange, privilege escalation, exfiltration, and additional malware delivery. ASEC also observed a previously unknown infostealer with wiretapping features, underscoring RedEyes’ focus on monitoring specific individuals.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1c1136c12d0535f4b90e32aa36070682 | 2023-06-12 | 2025-09-26 |
| HASH | 1352abf9de97a0faf8645547211c3be7 | 2023-06-12 | 2025-09-26 |
| HASH | 3277e0232ed6715f2bae526686232e06 | 2023-06-12 | 2025-09-26 |
| HASH | 59804449f5670b4b9b3b13efdb296abb | 2023-06-12 | 2025-09-26 |
| HASH | 3c475d80f5f6272234da821cc418a6f7 | 2023-06-12 | 2025-09-26 |
| IPv4 | 172.93.181.249 | 2023-06-12 | 2025-09-26 |
| HASH | f44bf949abead4af0966436168610bcc | 2023-06-12 | 2023-06-21 |