Threat Advisory

North Korean ScarCruft Attackers Exploit LNK Files to Spread RokRAT

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers provide insights into RokRAT, a North Korean state-sponsored remote access trojan used by ScarCruft. RokRAT, a sophisticated RAT, plays a crucial role in unauthorized access and sensitive data exfiltration within the attack chain. ScarCruft, a cyber espionage group linked to the North Korean government, has been active since 2012, primarily targeting entities in South Korea. The group is suspected to be a subordinate unit of North Korea's Ministry of State Security (MSS). The group relies heavily on social engineering techniques to spear-phish victims and infiltrate target networks with malicious payloads. The group exploits vulnerabilities in Hancom's Hangul Word Processor (HWP), a popular productivity software in South Korea, to distribute their distinctive malware, known as RokRAT.[/subscribe_to_unlock_form]

Summary:

Researchers provide insights into RokRAT, a North Korean state-sponsored remote access trojan used by ScarCruft. RokRAT, a sophisticated RAT, plays a crucial role in unauthorized access and sensitive data exfiltration within the attack chain. ScarCruft, a cyber espionage group linked to the North Korean government, has been active since 2012, primarily targeting entities in South Korea. The group is suspected to be a subordinate unit of North Korea's Ministry of State Security (MSS). The group relies heavily on social engineering techniques to spear-phish victims and infiltrate target networks with malicious payloads. The group exploits vulnerabilities in Hancom's Hangul Word Processor (HWP), a popular productivity software in South Korea, to distribute their distinctive malware, known as RokRAT.[emaillocker id="1283"]

Attack Chain

The execution process begins by gathering information about the victim's computer. To evade detection, the malware assesses whether it is being monitored by a debugger. The malware measures the time taken for specific operations or code sections by making API calls. By comparing the elapsed time with expected values, it can determine if its execution is being hindered by debugging activities. The malware captures a screenshot and saves it in the TEMP folder to be sent to the C2 (Command and Control) server. The malware also gathers information about the logical drives on the system. The malware utilizes multiple cloud providers to establish communication with the server. The URLs are stored in plaintext, and the malware employs authorization headers to validate the session. If the session cannot be validated, the execution is halted.

The API is used to execute the shellcode. The attacker initiates a command from the C2, which RokRAT executes using cmd.exe. The malware scans for specific file extensions and then exfiltrates the contents of those files to the C2 server.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/n-korean-scarcruft-hackers-exploit.html

[/emaillocker]
crossmenu