ScarCruft针对韩国金融、高校下发Chinotto后门的攻击活动分析 - 安恒威胁情报中心

2023-08-30 安恒信息 ScarCruft analysis of attack activities targeting South Korean financial institutions and universities with Chinotto backdoors - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2023/08/30/scarcruft-deliver-chinotto/

Thumbnail for ScarCruft针对韩国金融、高校下发Chinotto后门的攻击活动分析 - 安恒威胁情报中心

ScarCruft targeted South Korean financial institutions, universities, and individual users with ZIP/RAR lures that delivered Chinotto PowerShell backdoors or an InfoStealer. The campaign used Korean financial and insurance themes, including encrypted decoy documents that required a target birthdate or password, and malicious LNK/CHM files hosted on public websites. One chain unpacked a fake XLSX LNK and BAT script, persisted via `UserProfileSafeBackup.bat`, invoked mshta, and contacted `75.119.136.207` and `bian0151.cafe24.com` for Chinotto commands. Other CHM chains masqueraded as HanaCard, KBank, DB Insurance, or university-related documents, with the InfoStealer collecting browser, recent-file, and registry artifacts before uploading them to attacker infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ableinfo.co.kr 2023-08-30 2025-01-12
HASH fa03b0248a109a86eaddba108ebfcb14 2023-08-30 2023-12-01
HASH 16a34b0e194b3f825a19db5363df4cca 2023-08-30 2023-12-01
HASH 0eb8db3cbde470407f942fd63afe42b8 2023-08-22 2023-09-06
HASH 2d444b6f72c8327d1d155faa2cca7fd7 2023-08-22 2023-09-06
URL http://bian0151.cafe24.com/admi… 2023-08-22 2023-09-06
DOMAIN bian0151.cafe24.com 2023-08-22 2023-09-06
IPv4 75.119.136.207 2023-07-11 2023-09-06
HASH 74dd8338fedcb9c1d098b38e19a65d48 2023-08-30 2023-08-30
HASH c52f99555875c34bd1bd531ffab65234 2023-08-30 2023-08-30
URL http://ableinfo.co.kr/member/ 2023-08-30 2023-08-30
URL http://bian0151.cafe24.com/memb… 2023-08-30 2023-08-30
HASH 66165dfb784cbcb442e4767f0ca4f469 2023-08-22 2023-08-30
URL https://tosals.ink/uEH5J.html 2023-07-21 2023-08-30
DOMAIN tosals.ink 2023-07-21 2023-08-30
URL https://atusay.lat/kxydo 2023-07-20 2023-08-30
DOMAIN atusay.lat 2023-07-20 2023-08-30

Related Actors

Related Reports

« Back