#Fakecheck
Incident/Operation
2023-08-25 • 疑似 APT37 新攻击武器Fakecheck分析报告
FakeCheck is a .NET remote-access Trojan delivered through Korean-language malicious CHM files themed around insurance, securities, finance, and communications bills. Embedded scripts decompiled the help file, executed an obfuscated JScript stage, downloaded the payload, and attempted persistence while checking for AhnLab security software. FakeCheck gathered disk and file information and used a largely bogus .NET-version check as a decoy. Some researchers associated the activity with APT37, but the analyzed samples and tradecraft did not match the researchers’ established APT37 corpus, leaving attribution uncertain between a new APT37 toolset and a different actor.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days