APT-C-28(ScarCruft)组织针对韩国部署Chinotto组件的活动分析

2023-12-01 • Qihoo360 • Analysis of the activities of APT-C-28 (ScarCruft) targeting the deployment of Chinotto components in South Korea •

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247494166&idx=1&sn=c88fd9344d0a8b9597260d5d80dc7fce&chksm=f9c1d91fceb6500915a0e9cc5ecdf12d4202892a0b653e348a91f9769c583bdb33a212d22c16&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-28(ScarCruft)组织针对韩国部署Chinotto组件的活动分析

360 Threat Intelligence Center analyzed APT-C-28, also known as ScarCruft, activity targeting South Korea with Chinotto components. The excerpt shows LNK based delivery commands that extract Korean-language decoy documents and batch scripts from oversized shortcut files, including a seminar-themed PDF and a survey spreadsheet. The report says the group used phishing pages to collect victims' personal information, configured persistence on each execution, and varied remote connections loaded at startup. 360 assessed the memory-loaded Chinotto Trojan as feature rich and likely only partly disclosed based on the observed command set.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 196f2a674a61dbeae0ec2b0b7b9ac8d… 2023-08-30 2023-12-01
HASH 35ae5d7b0bd61b3ca18b1575e132c50… 2023-08-30 2023-12-01

Related Actors

Related Reports

« Back