APT-C-28(ScarCruft)组织利用无文件方式投递RokRat的攻击活动分析

2025-02-19 Qihoo360 Analysis of APT-C-28 (ScarCruft) attack activity delivering RokRAT filelessly

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247505583&idx=1&sn=8ed8a00690db7f06260546c6a5142380

Thumbnail for APT-C-28(ScarCruft)组织利用无文件方式投递RokRat的攻击活动分析

APT-C-28 (ScarCruft), also known as APT37, Reaper, and Group123, targeted South Korean government and enterprise personnel with phishing archives containing malicious LNK files. The LNK files used PowerShell to extract decoy documents, malicious BAT and PowerShell scripts, and encrypted RokRat Shellcode, which was decrypted with XOR and executed in memory. The decrypted payload produced a RokRat PE compiled in October 2024, with core capabilities consistent with earlier RokRat versions but changes in delivery path and operational strategy. The campaign embedded the encrypted payload directly in the LNK instead of retrieving it from cloud services, likely reflecting adaptation after malicious cloud links were rapidly disabled. RokRat artifacts included a Googlebot-like User-Agent and the string "--wwjaughalvncjwiajs--", with commands for screenshots, process collection, file enumeration, payload retrieval, execution, and cleanup.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c045b9da0456430268861da18735f7e… 2024-11-01 2025-06-27
HASH cfc814a16547dd4e92607bd42d2722c… 2025-02-19 2025-03-10
HASH 7df7ad7b88887a06b559cd453e7b652… 2025-01-21 2025-03-10
HASH 208dd2b4be4ab3491b93cbef8a4e9a5… 2025-02-19 2025-02-19
HASH 7f86a44faf1d624f9a58455425d644e… 2025-02-19 2025-02-19
HASH 20e4c50dd521b8561510e15f99c6774… 2024-11-01 2025-02-19
HASH 625c361380bf472c16edec72f5c3a87… 2024-11-01 2025-02-19
HASH 707e8cb56f32209ca837f2853801256… 2024-11-01 2025-02-19
HASH 0af3b744c9d5deeb1697ce2a3565624b 2024-04-23 2025-02-19

Related Actors

Related Reports

« Back