ScarCruft利用福岛核废水排放话题进行攻击活动

2023-09-06 安恒信息 ScarCruft uses the topic of Fukushima nuclear wastewater discharge to carry out attacks

https://starmap.dbappsecurity.com.cn/blog/articles/2023/09/06/scarcruft-fukushima/

Thumbnail for ScarCruft利用福岛核废水排放话题进行攻击活动

ScarCruft used the Fukushima treated-water discharge controversy as a social-engineering theme against Korean users, distributing a `Fukushima.rar` archive containing a CHM file. When opened, the CHM executed remote code from `navercorp.ru/dashboard/image/202302/4.html` and displayed decoy content about Japanese beer sales after the discharge to distract the victim. The payload chain again launched a Chinotto backdoor through PowerShell, with C2-style communication to `navercorp.ru/dashboard/image/202302/com.php?U=`. The captured Chinotto variant retained file theft and upload capabilities while adding scheduled-task creation for persistence and file-deletion functionality to remove traces.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
DOMAIN navercorp.ru 2023-09-04 2023-09-08
HASH 9e6a2914a35256dd450db549fb975f45 2023-09-06 2023-09-07
HASH a8c06b1f34c430358a2db30988066def 2023-09-06 2023-09-06
URL http://navercorp.ru/dashboard/i… 2023-09-06 2023-09-06

Related Actors

Related Reports

« Back