Inky Squid
2021-08-17 • Volexity • North Korean APT InkySquid Infects Victims Using …
Volexity introduced the name InkySquid in an August 2021 report describing a North Korean threat actor whose activity broadly corresponds to what other researchers publicly track as ScarCruft or APT37. Volexity documented a strategic web compromise of a South Korean online newspaper covering North Korea-related news, in which malicious code injected into the site's scripts redirected Internet Explorer and Edge users to attacker infrastructure exploiting browser vulnerabilities, delivering a Cobalt Strike stager followed by a backdoor using cloud services such as Microsoft's Graph API for command and control. A follow-up investigation found the same backdoor deployed alongside RokRAT, a remote-access trojan previously attributed to ScarCruft, on a system belonging to an individual frequently targeted by North Korean actors, with the malware performing keylogging, clipboard theft, file collection, and encrypted exfiltration. A later analysis described the group as active for roughly a decade, relying on social engineering and n-day exploits against browsers and Korean word-processing software; researchers also attributed a macOS backdoor sharing RokRAT's cloud-based infrastructure and code structure to the same group, used to exfiltrate documents, screenshots, and keystrokes.
-
26
Related Actors
-
3
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster