RedEyes Group Wiretapping Individuals (APT37)

2023-06-21 Ahnlab

https://asec.ahnlab.com/en/54349/

Thumbnail for RedEyes Group Wiretapping Individuals (APT37)

ASEC attributed a May 2023 campaign to RedEyes/APT37, also known as ScarCruft/Reaper, targeting individuals such as North Korean defectors, human-rights activists, and university professors. The intrusion used spear-phishing attachments that paired a normal password-protected document with CHM malware disguised as a password file; executing the CHM launched MSHTA and a PowerShell backdoor with autorun persistence. Later stages used an Ably-based GoLang backdoor that retrieved its channel authentication key from GitHub, enabling command exchange, privilege escalation, exfiltration, and additional malware delivery. ASEC also observed a previously unknown infostealer with wiretapping features, underscoring RedEyes’ focus on monitoring specific individuals.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a14f88ec58a6b391a40821419efa37e… 2023-06-12 2025-09-26
HASH 56914bc6034073546d0e3c64c563e6f… 2023-06-12 2025-09-26
HASH 3277e0232ed6715f2bae526686232e06 2023-06-12 2025-09-26
HASH 026a290ece9da127678ef0cc4911d4d… 2023-06-12 2025-09-26
HASH 87827dbb93b3b1ac5c018b2a75c0eb9… 2023-06-12 2025-09-26
IPv4 172.93.181.249 2023-06-12 2025-09-26
HASH f44bf949abead4af0966436168610bcc 2023-06-12 2023-06-21

Related Actors

Related Reports

« Back