home.social

#apt37 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #apt37, aggregated by home.social.

fetched live
  1. APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks
    #APT37
    genians.co.kr/en/blog/threat_i

  2. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  3. Happy Friday everyone!

    It's always a good morning when you get news of some new MITRE ATT&CK Tactics, Techniques, or Sub-techniques! Nate Nelson highlights the new additions and discusses how #APT37 and #APT41 are adopting the techniques in recent attacks! Enjoy and Happy Hunting!

    DPRK Exploits 2 MITRE Sub-Techniques: Phantom DLL Hijacking, TCC Abuse
    darkreading.com/vulnerabilitie

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting! #readoftheday

  4. Happy Tuesday everyone!

    #APT37, aka #ScarCruft, is at it again! SentinelOne researchers noticed that they are targeting media organizations and others that are associated with North Korean affairs. The group leverages .LNK files, zip files, and phishing emails.

    I found this article most interesting because of the multiple types of file formats that were used, to include .bat and .dat files, involved in the campaign. They also use a custom backdoor known as #RokRat to aid in their attack. This is a great article and worth the time! Enjoy and Happy Hunting!

    Notable MITRE ATT&CK TTPs and Behaviors:
    TA0001 - Initial Access
    T1566.001 - Phishing: Spearphishing Attachment

    TA0002 - Execution
    T1059.001 - Command And Scripting Interpreter: Powershell
    T1204.001 - User Execution: Malicious Link

    sentinelone.com/labs/a-glimpse

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #gethunting

  5. NEW research on my blog!

    The evolution of North Korean threat group #APT37's Android spyware: #ROKRAT & #RambleOn

    In this research I perform a comparative analysis between ROKRAT & RambleOn, North Korean threat group APT37's Android malware.

    Link: 0x0v1.com/the-evolution-of-apt

    #threatintel #apt #reverseengineering #malware #spyware #northkorea

  6. In revisiting some old #APT37 samples, I wanted to take a look back at the #GOLDBACKDOOR dropper. Which actively targeted civil society & journalists based in South Korea.

    Here's in my reverse engineering analysis, I deep dive into this older malware campaign by the North Korean threat group.

    This is part of my project REarchive, where I look at historic APT campaigns that haven't been covered much publicly. Read here:
    0x0v1.com/rearchive-goldbackdo

    #malware #APT #northkorea #threatintel #reverseengineering

  7. Die vom nordkoreanischen Staat gesponserte Hackergruppe #ScarCruft (#APT37) hat die IT-Infrastruktur und den E-Mail-Server von NPO Mashinostroyeniya gehackt.

    NPO Mashinostroyeniya ist ein russischer Konstrukteur und Hersteller von Orbitalfahrzeugen, Raumfahrzeugen und taktischen Verteidigungs- und Angriffsraketen, die von der russischen und indischen Armee eingesetzt werden.

    #hack #russland #nordkorea #Opencarrot #windows

    bleepingcomputer.com/news/secu

    golem.de/news/angriff-aus-nord

  8. Just uploaded my #APT37 #ROKRAT shellcode decrypter script to my github. Hope this helps malware researchers out there

    github.com/0x0v1/MalwareRETool

  9. I just published a script that will assist malware researchers looking at #APT37's #ROKRAT to decode the PS reflection portion of the loader phase. It gives analysts the option to pull shellcode from the payload delivery host quickly for timely analysis.

    github.com/0x0v1/MalwareRETool

    I will later publish a script to deencrypt the shellcode for analysis - just need to clean a few things up in it.

  10. Happy Tuesday everyone! #APT37 is the topic of today's #readoftheday, specifically ThreatMon takes a deep-dive into the #RokRat malware, which is a remote access trojan (RAT). Enjoy and Happy Hunting!

    Link to article in the comments!

    ***AS usual I am going to leave one of the MITRE ATT&CK blank. I would like to see if any of you that see this can help FILL in that blank! If so, leave your thoughts in the comments OR send me a DM!***

    Notable MITRE ATT&CK TTPs:
    TA0007 - Discovery
    T1087 - Account Discovery
    T1083 - File and Directory Discovery
    T1018 - Remote System Discovery
    T1082 - System Information Discovery

    TA0009 - Collection
    T[What technique covers the threat actor capturing information under the TEMP folder?] - Good luck!

    TA0011 - Command And Control
    T1071.001 - Application Layer Protocol: Web Protocols

    TA0002 - Execution
    T1059.003 - Command and Scripting Interpreter: Windows Command Shell

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting