RedEyes (ScarCruft)'s CHM Malware Using the Topic of Fukushima Wastewater Release
2023-09-08 • Ahnlab •
AhnLab ASEC reported renewed CHM malware distribution assessed as likely RedEyes/ScarCruft activity, using Korean interest in the Fukushima wastewater release as the lure. The CHM file registers an mshta command under the HKCU Run key, then retrieves JavaScript from navercorp[.]ru to execute encoded PowerShell. The decoded backdoor maintains persistence, polls com.php with the victim computer and user name, and can upload or download files, enumerate file metadata, modify the registry, schedule tasks, rename files, and delete data. ASEC linked the command structure to earlier RedEyes CHM and M2RAT activity and listed Downloader/CHM.Generic plus the navercorp[.]ru URLs as indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 52f71fadf0ea5ffacd753e83a3d0af1a | 2023-09-04 | 2023-09-08 |
| URL | http://navercorp.ru/dashboard/i… | 2023-09-04 | 2023-09-08 |
| URL | http://navercorp.ru/dashboard/i… | 2023-09-04 | 2023-09-08 |
| DOMAIN | navercorp.ru | 2023-09-04 | 2023-09-08 |