APT-C-28(ScarCruft)组织针对能源方向投放Rokrat后门活动分析

2023-07-13 • Qihoo360 • Analysis of APT-C-28 (ScarCruft) organization's Rokrat backdoor activities targeting the energy direction •

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247492864&idx=1&sn=0af3b744c9d5deeb1697ce2a3565624b&chksm=f9c1d609ceb65f1f62c856e57004fe90fe059d688a7a858b483208cfe832b3d5ab77d13f3f1e&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-28(ScarCruft)组织针对能源方向投放Rokrat后门活动分析

360’s threat research team reported APT-C-28/ScarCruft activity using an energy-sector lure about the Sharara-to-Mellitah oil pipeline to deliver the RokRAT backdoor. The attack used a large padded LNK file containing a decoy PDF and malicious BAT logic, then PowerShell pulled an encrypted RokRAT payload from OneDrive, decrypted it, and ran it in memory. The RokRAT sample collected host and user details, supported file transfer, command execution, screenshots, and keylogging, and used cloud storage APIs including pCloud, Yandex, and Dropbox for command and file exchange. The report notes continuity with earlier RokRAT behavior, including familiar file naming, code structure, and HTTP content-type patterns.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4d3464b23dd4fb141c8fcc4cbf541832 2023-07-13 2023-07-13
HASH 5678196f512f8a531c7d85af8df4f40… 2023-06-06 2023-07-13
HASH 852607619f1de73d78b4e0de2cc5f37… 2023-05-15 2023-07-13
HASH 6753933cd54e4eba497c48d63c7418a… 2023-05-01 2023-07-13
HASH 732fca9be66ba2c40c5d05845540207… 2023-05-01 2023-07-13
URL https://1drv.ms/u/s!AjQNLvEE_CU… 2023-05-01 2023-07-13
URL https://api.onedrive.com/v1.0/s… 2023-05-01 2023-07-13

Related Actors

Related Reports

« Back