APT37 aka ScarCruft or RedEyes – Active IOCs

2024-11-01 Rewterz

https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-8

Thumbnail for APT37 aka ScarCruft or RedEyes – Active IOCs

APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group that mainly targets South Korea and has also operated across Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and the Middle East. The advisory links APT37 to RokRAT and Goldbackdoor, and says RedEyes expanded from CHM malware disguised as a Korean financial security email to RokRAT delivery through LNK files. RokRAT uses PowerShell launched from LNK content, collects machine data for target selection, communicates through cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive, and supports additional payload execution and data exfiltration. The IOC set includes multiple hashes tied to the LNK and RokRAT activity, including 89c0d2cc1e71b17449eec454161d60da and 707e8cb56f32209ca837f2853801256cd3490ed2cc4b3428dc5e4238848f226d.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c045b9da0456430268861da18735f7e… 2024-11-01 2025-06-27
HASH 20e4c50dd521b8561510e15f99c6774… 2024-11-01 2025-02-19
HASH 625c361380bf472c16edec72f5c3a87… 2024-11-01 2025-02-19
HASH 707e8cb56f32209ca837f2853801256… 2024-11-01 2025-02-19

Related Actors

Related Reports

« Back