개인을 도청하는 RedEyes 그룹 (APT37)

2023-06-12 Ahnlab RedEyes group eavesdropping on individuals (APT37)

https://asec.ahnlab.com/ko/53851/

Thumbnail for 개인을 도청하는 RedEyes 그룹 (APT37)

AhnLab reports that RedEyes, also known as APT37, ScarCruft, and Reaper, targeted individuals such as North Korean defectors, human-rights activists, and university professors in May 2023. The attack chain began with spear-phishing that paired a password-protected benign document with a CHM file posing as the password file; opening the CHM launched MSHTA to retrieve scripts from attacker infrastructure and install a PowerShell backdoor with Run-key persistence. The group used a Golang Ably-based backdoor that fetched a Base64-encoded channel key from GitHub, exchanged UP/DOWN messages over Ably for command execution, and then used COM hijacking and fileless execution to deploy an information stealer. ASEC named the stealer FadeStealer and described screenshot capture, removable-media and smartphone data theft, keylogging, microphone eavesdropping, RAR-compressed exfiltration every 30 minutes, and C2 paths on 172.93.181[.]249.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a14f88ec58a6b391a40821419efa37e… 2023-06-12 2025-09-26
HASH 56914bc6034073546d0e3c64c563e6f… 2023-06-12 2025-09-26
HASH 3277e0232ed6715f2bae526686232e06 2023-06-12 2025-09-26
HASH 026a290ece9da127678ef0cc4911d4d… 2023-06-12 2025-09-26
HASH 87827dbb93b3b1ac5c018b2a75c0eb9… 2023-06-12 2025-09-26
IPv4 172.93.181.249 2023-06-12 2025-09-26
HASH f44bf949abead4af0966436168610bcc 2023-06-12 2023-06-21

Related Actors

Related Reports

« Back