RedEyes Group Wiretapping Individuals (APT37)
2023-06-21 • Ahnlab •
ASEC attributed a May 2023 campaign to RedEyes/APT37, also known as ScarCruft/Reaper, targeting individuals such as North Korean defectors, human-rights activists, and university professors. The intrusion used spear-phishing attachments that paired a normal password-protected document with CHM malware disguised as a password file; executing the CHM launched MSHTA and a PowerShell backdoor with autorun persistence. Later stages used an Ably-based GoLang backdoor that retrieved its channel authentication key from GitHub, enabling command exchange, privilege escalation, exfiltration, and additional malware delivery. ASEC also observed a previously unknown infostealer with wiretapping features, underscoring RedEyes’ focus on monitoring specific individuals.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a14f88ec58a6b391a40821419efa37e… | 2023-06-12 | 2025-09-26 |
| HASH | 56914bc6034073546d0e3c64c563e6f… | 2023-06-12 | 2025-09-26 |
| HASH | 3277e0232ed6715f2bae526686232e06 | 2023-06-12 | 2025-09-26 |
| HASH | 026a290ece9da127678ef0cc4911d4d… | 2023-06-12 | 2025-09-26 |
| HASH | 87827dbb93b3b1ac5c018b2a75c0eb9… | 2023-06-12 | 2025-09-26 |
| IPv4 | 172.93.181.249 | 2023-06-12 | 2025-09-26 |
| HASH | f44bf949abead4af0966436168610bcc | 2023-06-12 | 2023-06-21 |