#Matryoshka

Incident/Operation

2021-07-14 • Matryoshka : Variant of ROKRAT, APT37 (Scarcruft)

Matryoshka is an evolved ROKRAT malware variant associated with the North Korean-linked ScarCruft group, also known as APT37. It was deployed in a December 2020 watering-hole attack against users visiting a compromised website with a vulnerable Internet Explorer version. The multistage chain used PowerShell, downloaded a Ruby runtime and obfuscated Ruby script, decoded shellcode and an embedded Windows executable, and disguised files as legitimate drivers. The final malware collected victim information and exfiltrated it through cloud services.

Tagged Reports

« Back