Scarcruft Bolsters Arsenal for targeting individual Android devices

2023-03-23 S2W

https://medium.com/s2wblog/scarcruft-bolsters-arsenal-for-targeting-individual-android-devices-97d2bcef4ab

Thumbnail for Scarcruft Bolsters Arsenal for targeting individual Android devices

At the end of 2017, the group also carried out an attack campaign targeting North Korean human rights organization officials and journalists from North Korean media outlets to induce the installation of malicious APKs through KakaoTalk, the most popular messenger in South Korea. The Scarcruft Group (aka APT37), a North Korean APT group, is believed to have been active since 2016 and continues to carry out attacks against institutions and political organizations around the world until 2023. RambleOn) has been used by the Scarcruft APT group since at least 2019 to target Android devices. FCM is a service that specializes in message delivery within Firebase and was also used in the mobile malware used by the Kimsuky group that we disclosed last year.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5dde5f5fcc1ebfd932e1ef0bfcc7b272 2023-03-23 2023-03-23
HASH 15470bafbaf3841bac1813881e6524fa 2023-03-23 2023-03-23
HASH a97e22b8ca16452a4ddcb32284d7c7a7 2023-03-23 2023-03-23
HASH 214ead5c75899b8d1382e558e542574a 2023-03-23 2023-03-23
HASH fe11b08764fba51236325be852ca1406 2023-03-23 2023-03-23
HASH 1d4683844c8429ad141f9f66bcf29728 2023-03-23 2023-03-23
HASH 580f22dde975ac5e3544f3a74f4a91b9 2023-03-23 2023-03-23
HASH 445922b01b3f8f463cb9f48d74efd9a8 2023-03-23 2023-03-23
HASH 3ae92bc233dd6a4412aa77da4dc44a19 2023-03-23 2023-03-23
HASH be6f13d6e7ae5039aed46d1f8844f3ee 2023-03-23 2023-03-23
HASH 27e0dcceb68c03b246874c9fcc9b744e 2023-03-23 2023-03-23
HASH 72182f83e771fcaaa1e86c7c932014cb 2023-03-23 2023-03-23
HASH 957ebfbd0b23a164529d7510ca89ddae 2023-03-23 2023-03-23
HASH 0711102cbfcf18a3672a892c4ea31ad1 2023-03-23 2023-03-23
HASH 97a9ab76af215241ad2a07856b40242e 2023-03-23 2023-03-23
HASH 759b26631a660d82f6a93621991c4292 2023-03-23 2023-03-23
HASH e4f781e00bc48f88a717095deb78be6f 2023-03-23 2023-03-23
HASH 97a750f33812195cc2add4ebd120b468 2023-03-23 2023-03-23
HASH ae767e4658a5d235ec614eaa8655da0d 2023-03-23 2023-03-23
HASH 464df52f091f95a561474d4de62a821b 2023-03-23 2023-03-23
HASH a90e3bd0e2de1b6a6bec269dc0f09369 2023-03-23 2023-03-23
HASH f58fed1e492f40d28e0bc38dc0f76b35 2023-03-23 2023-03-23
HASH 8092bb293352ef572464c682e81f329f 2023-03-23 2023-03-23
HASH 97ecdb46b8325a845e998cfe3bd2262e 2023-03-23 2023-03-23
HASH 1f2c23c7c9ecb28bfdc6627a3ad23783 2023-03-23 2023-03-23
HASH d7723de89903a04b93c7a9a92d8309c2 2023-03-23 2023-03-23
HASH ce3104fe4184558feea707368846c226 2023-03-23 2023-03-23
HASH 97856a842ff8161576fee5ad3fd0ec67 2023-03-23 2023-03-23
HASH 89c669739066ac655a1e2b772bb020f3 2023-03-23 2023-03-23

Related Actors

Related Reports

« Back