ScarCruft surveilling North Korean defectors and human rights activists

2021-11-29 Kaspersky

https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/

Thumbnail for ScarCruft surveilling North Korean defectors and human rights activists

Kaspersky describes ScarCruft/APT37/Temp.Reaper activity against North Korean defectors, journalists covering North Korea, and Korean Peninsula-related organizations after assisting a compromised news organization. The investigation found a victim infected with PowerShell malware, evidence of months-long surveillance and data theft, and attempts to phish the victim’s associates with stolen Facebook and email credentials. ScarCruft used a password-protected RAR archive carrying a malicious Word document with a North Korea-themed lure; the macro chain checked for Kaspersky components, modified Office macro trust settings, decrypted shellcode, and attempted to fetch a next-stage payload from a defanged OneDrive URL. Related PowerShell, Windows executable, and Android malware families shared HTTP-based command-and-control logic, and logs from compromised servers exposed additional South Korean victims and infrastructure used since early 2021.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f17502d3e12615b0fa8868472a4eabfb 2021-11-29 2021-12-04
HASH 72e5b8ea33aeb083631d1e8b302e76af 2021-11-29 2021-12-04
HASH 5a7ef48fe0e8ae65733db64ddb7f2478 2021-11-29 2021-12-04
HASH c155f49f0a9042d6df68fb593968e110 2021-11-29 2021-12-04
DOMAIN kjdnc.gp114.net 2020-07-14 2021-12-04
HASH c7c3b03108f2386022793ed29e621343 2021-11-29 2021-11-29
HASH 55afe67b0cd4a01f3a9a6621c26b1a49 2021-11-29 2021-11-29
HASH 93bcbf59ac14e14c1c39a18d8ddf28ee 2021-11-29 2021-11-29
HASH c9fb6f127ca18a3c2cf94e405df67f51 2021-11-29 2021-11-29
HASH f08d7f7593b1456a087eb9922507c743 2021-11-29 2021-11-29
HASH cff9d2f8dae891bd5549bde869fe8b7a 2021-11-29 2021-11-29
HASH 3490053ea54dfc0af2e419be96462b08 2021-11-29 2021-11-29
HASH 7d5283a844c5d17881e91a5909a5af3c 2021-11-29 2021-11-29
HASH cba17c78b84d1e440722178a97886bb7 2021-11-29 2021-11-29
HASH 71b63d2c839c765f1f110dc898e79d67 2021-11-29 2021-11-29
HASH 0dd115c565615651236fffaaf736e377 2021-11-29 2021-11-29
HASH 00df5bbac9ad059c441e8fef9fefc3c1 2021-11-29 2021-11-29
HASH e9e13dd4434e2a2392228712f73c98ef 2021-11-29 2021-11-29
HASH 56f3d2bcf67cf9f7b7d16ce8a5f8140a 2021-11-29 2021-11-29
HASH 04ddb77e44ac13c78d6cb304d71e2b86 2021-11-29 2021-11-29
HASH 97b35c34d600088e2a281c3874035f59 2021-11-29 2021-11-29
HASH baa9b34f152076ecc4e01e35ecc2de18 2021-11-29 2021-11-29
HASH d8ad81bafd18658c52564bbdc89a7db2 2021-11-29 2021-11-29
HASH b06c203db2bad2363caed1c0c11951ae 2021-11-29 2021-11-29
URL http://haeundaejugong.com/data/… 2021-11-29 2021-11-29
URL http://doseoul.com/bbs/data/hnc… 2021-11-29 2021-11-29
URL http://luminix.kr/bbs/data/proc… 2021-11-29 2021-11-29
URL https://1drv.ms/u/s!AjUrd9huMpQ… 2021-11-29 2021-11-29
URL http://hz11.cn/jquery-ui-1.10.4… 2021-11-29 2021-11-29
URL http://www.djsm.co.kr/js/201708… 2021-11-29 2021-11-29
URL http://kumdo.org/admin/cont/do.… 2021-11-29 2021-11-29
URL http://haeundaejugong.com/edito… 2021-11-29 2021-11-29
URL http://luminix.openhaja.com/bbs… 2021-11-29 2021-11-29
URL https://api.onedrive.com/v1.0/s… 2021-11-29 2021-11-29
DOMAIN luminix.openhaja.com 2021-11-29 2021-11-29
DOMAIN hz11.cn 2021-11-29 2021-11-29
DOMAIN doseoul.com 2021-11-29 2021-11-29
DOMAIN luminix.kr 2021-11-29 2021-11-29
DOMAIN haeundaejugong.com 2020-11-25 2021-11-29
URL http://kjdnc.gp114.net/data/log… 2020-07-14 2021-11-29

Related Actors

Related Reports

2021-12-02 • 50% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1573.001 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004 #T0865
Shares tags: T1082, T1140, T1041 • Published within a week
« Back