개인을 도청하는 RedEyes 그룹 (APT37)
2023-06-12 • Ahnlab • RedEyes group eavesdropping on individuals (APT37) •
AhnLab reports that RedEyes, also known as APT37, ScarCruft, and Reaper, targeted individuals such as North Korean defectors, human-rights activists, and university professors in May 2023. The attack chain began with spear-phishing that paired a password-protected benign document with a CHM file posing as the password file; opening the CHM launched MSHTA to retrieve scripts from attacker infrastructure and install a PowerShell backdoor with Run-key persistence. The group used a Golang Ably-based backdoor that fetched a Base64-encoded channel key from GitHub, exchanged UP/DOWN messages over Ably for command execution, and then used COM hijacking and fileless execution to deploy an information stealer. ASEC named the stealer FadeStealer and described screenshot capture, removable-media and smartphone data theft, keylogging, microphone eavesdropping, RAR-compressed exfiltration every 30 minutes, and C2 paths on 172.93.181[.]249.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a14f88ec58a6b391a40821419efa37e… | 2023-06-12 | 2025-09-26 |
| HASH | 56914bc6034073546d0e3c64c563e6f… | 2023-06-12 | 2025-09-26 |
| HASH | 3277e0232ed6715f2bae526686232e06 | 2023-06-12 | 2025-09-26 |
| HASH | 026a290ece9da127678ef0cc4911d4d… | 2023-06-12 | 2025-09-26 |
| HASH | 87827dbb93b3b1ac5c018b2a75c0eb9… | 2023-06-12 | 2025-09-26 |
| IPv4 | 172.93.181.249 | 2023-06-12 | 2025-09-26 |
| HASH | f44bf949abead4af0966436168610bcc | 2023-06-12 | 2023-06-21 |