RedEyes (ScarCruft)'s CHM Malware Using the Topic of Fukushima Wastewater Release

2023-09-08 Ahnlab

https://asec.ahnlab.com/en/56857/

Thumbnail for RedEyes (ScarCruft)'s CHM Malware Using the Topic of Fukushima Wastewater Release

AhnLab ASEC reported renewed CHM malware distribution assessed as likely RedEyes/ScarCruft activity, using Korean interest in the Fukushima wastewater release as the lure. The CHM file registers an mshta command under the HKCU Run key, then retrieves JavaScript from navercorp[.]ru to execute encoded PowerShell. The decoded backdoor maintains persistence, polls com.php with the victim computer and user name, and can upload or download files, enumerate file metadata, modify the registry, schedule tasks, rename files, and delete data. ASEC linked the command structure to earlier RedEyes CHM and M2RAT activity and listed Downloader/CHM.Generic plus the navercorp[.]ru URLs as indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 52f71fadf0ea5ffacd753e83a3d0af1a 2023-09-04 2023-09-08
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
DOMAIN navercorp.ru 2023-09-04 2023-09-08

Related Actors

Related Reports

« Back