Inky Squid

2021-08-17 • VolexityNorth Korean APT InkySquid Infects Victims Using …

Volexity introduced the name InkySquid in an August 2021 report describing a North Korean threat actor whose activity broadly corresponds to what other researchers publicly track as ScarCruft or APT37. Volexity documented a strategic web compromise of a South Korean online newspaper covering North Korea-related news, in which malicious code injected into the site's scripts redirected Internet Explorer and Edge users to attacker infrastructure exploiting browser vulnerabilities, delivering a Cobalt Strike stager followed by a backdoor using cloud services such as Microsoft's Graph API for command and control. A follow-up investigation found the same backdoor deployed alongside RokRAT, a remote-access trojan previously attributed to ScarCruft, on a system belonging to an individual frequently targeted by North Korean actors, with the malware performing keylogging, clipboard theft, file collection, and encrypted exfiltration. A later analysis described the group as active for roughly a decade, relying on social engineering and n-day exploits against browsers and Korean word-processing software; researchers also attributed a macOS backdoor sharing RokRAT's cloud-based infrastructure and code structure to the same group, used to exfiltrate documents, screenshots, and keystrokes.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster