Suspected APT37 New Attack Weapon Fakecheck Analysis Report
2023-08-25 • Knownsec •
Knownsec 404 analyzed malicious CHM samples using Korean-language decoys themed around insurance, securities, finance, and communications bills, with targeting directed at South Korea. The CHM attack chain decompiled itself, released files under a public user directory, executed a JSE script, downloaded a payload as alg.exe, and showed code overlap with CHM activity previously disclosed by AhnLab. The final payload, named FakeCheck by the researchers, is a .NET RAT that collects host, disk, browser, bookmark, saved-password, and recent-file data, stores the results under the public pictures directory, uploads them to C2, and executes commands received from the server. Although some researchers attributed the activity to APT37, Knownsec states that the observed samples and TTPs do not provide direct evidence for that attribution and could represent new APT37 tradecraft or another actor using similar CHM techniques.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 01e7405ddd5545ffb4a57040acc4b6f… | 2023-08-25 | 2023-09-13 |
| HASH | a1f6ae788bf3f9ae17893f3b12d557f… | 2023-08-25 | 2023-09-13 |
| HASH | 012063e0b7b4f7f3ce50574797112f9… | 2023-08-25 | 2023-09-13 |
| HASH | f5e46e18facc6f8fde6658b96dcd379… | 2023-08-25 | 2023-09-13 |
| HASH | 578689cb4b06c4d3f1850e4379c4b31… | 2023-08-25 | 2023-09-13 |
| URL | https://tosals.ink/uEH5J.html | 2023-07-21 | 2023-08-30 |
| DOMAIN | tosals.ink | 2023-07-21 | 2023-08-30 |
| HASH | 37feb1d71c6458f71b27dc1ba7cb436… | 2023-08-25 | 2023-08-25 |
| HASH | 2b2583019d83e657c219dd6510060f9… | 2023-08-25 | 2023-08-25 |
| URL | https://oebil.lat/zyofl | 2023-08-25 | 2023-08-25 |
| URL | https://giath.xyz/maiqt | 2023-08-25 | 2023-08-25 |
| URL | https://bajut.pro/jdkvr | 2023-08-25 | 2023-08-25 |
| DOMAIN | for.net | 2023-08-25 | 2023-08-25 |
| DOMAIN | oebil.lat | 2023-08-25 | 2023-08-25 |
| DOMAIN | giath.xyz | 2023-08-25 | 2023-08-25 |
| DOMAIN | bajut.pro | 2023-08-25 | 2023-08-25 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |