ScarCruft利用福岛核废水排放话题进行攻击活动
2023-09-06 • 安恒信息 • ScarCruft uses the topic of Fukushima nuclear wastewater discharge to carry out attacks •
https://starmap.dbappsecurity.com.cn/blog/articles/2023/09/06/scarcruft-fukushima/
ScarCruft used the Fukushima treated-water discharge controversy as a social-engineering theme against Korean users, distributing a `Fukushima.rar` archive containing a CHM file. When opened, the CHM executed remote code from `navercorp.ru/dashboard/image/202302/4.html` and displayed decoy content about Japanese beer sales after the discharge to distract the victim. The payload chain again launched a Chinotto backdoor through PowerShell, with C2-style communication to `navercorp.ru/dashboard/image/202302/com.php?U=`. The captured Chinotto variant retained file theft and upload capabilities while adding scheduled-task creation for persistence and file-deletion functionality to remove traces.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://navercorp.ru/dashboard/i… | 2023-09-04 | 2023-09-08 |
| DOMAIN | navercorp.ru | 2023-09-04 | 2023-09-08 |
| HASH | 9e6a2914a35256dd450db549fb975f45 | 2023-09-06 | 2023-09-07 |
| HASH | a8c06b1f34c430358a2db30988066def | 2023-09-06 | 2023-09-06 |
| URL | http://navercorp.ru/dashboard/i… | 2023-09-06 | 2023-09-06 |