ITG10

2023-06-06 • IBMhttps://exchange.xforce.ibmcloud.com/threat-group/guid:145ab71913e04e1aa468ab44a597460c?_ga=2.149231730.579199315.1686140220-2051710342.1686140220&_gl=1*119zwyw*_ga*MjA1MTcxMDM0Mi4xNjg2MTQwMjIw*_ga_FYECCCS21D*MTY4NjE0MDIyMC4xLjAuMTY4NjE0MDI0MS4wLjAuMA..

ITG10 is IBM Security X-Force’s designation for a threat group whose activity overlaps with APT37 and ScarCruft. X-Force publicly described the cluster in June 2023 after uncovering an April 2023 phishing campaign that delivered RokRAT through malicious Windows shortcut files and obfuscated PowerShell. The observed lures impersonated credible senders and referenced South Korean parliamentary committees, broadcasters, think tanks, energy projects, manufacturing, and supply chains. X-Force assessed that probable targets included South Korean government personnel, universities, researchers, journalists, dissidents, and organizations holding strategic, political, or military information concerning the Korean Peninsula. The campaign used ZIP or ISO containers, decoy documents, LNK files, scripts, and cloud-hosted payloads. RokRAT provided command execution, file transfer, data exfiltration, and keylogging capabilities, supporting an intelligence-collection objective aligned with North Korean interests.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster