APT37 aka ScarCruft or RedEyes – Active IOCs

2024-11-14 Rewterz

https://www.rewterz.com/threat-advisory/apt37-aka-scarcruft-or-redeyes-active-iocs-37243

Thumbnail for APT37 aka ScarCruft or RedEyes – Active IOCs

APT37, also known as ScarCruft or RedEyes, is described as a North Korean espionage group active since at least 2012, with primary targeting in South Korea and operations also reported in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and the Middle East. The advisory highlights recent RedEyes activity distributing RokRAT through LNK files after earlier CHM lures impersonated Korean financial security email. RokRAT collects host data, runs additional payloads, exfiltrates information, and uses cloud services such as Dropbox, pCloud, Yandex Cloud, and OneDrive for C2 to blend with legitimate traffic. The source provides active hash IOCs for hunting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bb83597cdf057db754def79d3f94b6c… 2024-11-14 2025-01-07
HASH 13cc69320ed1e1422d13c3799998050… 2024-11-14 2024-11-14
HASH 0ea29853d7300b8dbd4ddea9923ad79… 2024-11-14 2024-11-14

Related Actors

Related Reports

« Back