home.social

#apt37 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #apt37, aggregated by home.social.

fetched live
  1. Discover how suspected North Korean hackers use the Ted Backdoor HAProxy malware and CurlRAT to infiltrate South Korean organizations and steal sensitive data.

    #TedBackdoor #HAProxy #CurlRAT #CyberSecurity #APT37

    meterpreter.org/ted-backdoor-h

  2. crond, sshd, polkitd: la backdoor nordcoreana Ted infetta i demoni Linux nascosta dentro HAProxy

    Rapid7 documenta una campagna APT37 che troianizza HAProxy e i servizi di sistema Linux (crond, sshd, polkitd, agetty, atd) per spiare aziende sudcoreane di media e automotive. La backdoor Ted e il RAT companion CurlRAT restano invisibili per mesi grazie a timestamp falsificati e log ripuliti chirurgicamente.

    insicurezzadigitale.com/crond-

  3. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37.

    Pulse ID: 6a9af7a5158ae188847551b5
    Pulse Link: otx.alienvault.com/pulse/6a9af
    Pulse Author: AlienVault
    Created: 2026-09-04 16:53:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #BackDoor #CredentialHarvesting #CyberSecurity #DPRK #Encryption #HTTP #InfoSec #KeyLogger #Korea #Linux #Nim #OTX #OpenThreatExchange #Proxy #RAT #RCE #RemoteCommandExecution #SSH #SSL #SouthKorea #Trojan #bot #AlienVault

  4. ScarCruft Targets Microsoft Users with NarwhalRAT Malware

    Beware of fake Microsoft account alerts! A sneaky North Korean hacking group, ScarCruft, is sending phishing emails that mimic Microsoft security notifications to trick you into downloading the NarwhalRAT malware.

    osintsights.com/scarcruft-targ

    #Scarcruft #Apt37 #Microsoft #Narwhalrat #NorthKorea

  5. 📰 North Korean APT ScarCruft Hits Gaming Platform in Supply-Chain Attack

    North Korean APT ScarCruft (APT37) targets gamers in a supply-chain attack, compromising a gaming site to distribute Android spyware. The 'BirdCall' backdoor spies on ethnic Koreans in China. 🕵️‍♂️ #APT37 #ScarCruft #CyberSecurity #Android

    🔗 cyber.netsecops.io

  6. ScarCruft APT Exploits Yanbian Gaming Platform for Intelligence Gathering

    Meet ScarCruft, a notorious North Korea-aligned espionage group that's been caught exploiting a popular gaming platform in China to gather intel on its users. The group trojanized a site serving traditional Yanbian-themed games, compromising both Windows and Android software.

    osintsights.com/scarcruft-apt-

    #Scarcruft #Apt37 #SupplyChain #Espionage #NationState

  7. ScarCruft hackers deploy BirdCall malware via gaming platform.

    North Korean hackers APT37, also known as ScarCruft, have cleverly expanded their BirdCall malware to target Android devices, adapting their Windows backdoor to spy on mobile users. They even used a popular gaming platform to sneak the malware onto unsuspecting devices.

    osintsights.com/scarcruft-hack

    #Apt37 #Scarcruft #RicochetChollima #BirdcallMalware #AndroidSpyware

  8. AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency

    Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.

    osintsights.com/ai-assisted-co

    #MaliciousNpmDependency #AiassistedCode #CryptoWallets #FamousChollima #Apt37

  9. APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks
    #APT37
    genians.co.kr/en/blog/threat_i

  10. North Korean Hackers Use Facebook to Distribute RokRAT Malware A state-sponsored North Korean hacking group has been linked to a new social engineering campaign that uses Facebook friend requests t...

    #Security #APT37 #Facebook #security #North #Korean #hackers #RokRAT #social #engineering

    Origin | Interest | Match
  11. APT37 Exploits Facebook for RokRAT Malware Delivery

    North Korean hackers APT37 have cleverly turned Facebook friend requests into a sneaky way to deliver RokRAT malware, exploiting our natural tendency to trust social connections. By accepting a friend request, victims unwittingly open the door to a remote access trojan that can compromise their device.

    osintsights.com/apt37-exploits

    #Apt37 #Rokrat #SocialEngineering #MalwareDelivery #NorthKorea

  12. APT37 abusing .LNK files with GitHub-based C2 in targeted campaign against South Korean organizations and supply chain partners. Malicious shortcuts execute PowerShell, deploy XenoRAT for remote access and keylogging. Detection challenge: legitimate GitHub traffic masks command execution. Fortinet researchers identified deliberate targeting of financial services, defense contractors, critical infrastructure handling sensitive government contracts. #APT37...

    bit.ly/4vdNa42

  13. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  14. South Korean researchers (Genians) report that APT37 is abusing Google Find Hub to track victims and remotely wipe Android devices.

    The attackers use phished Google credentials to access legitimate Find Hub functions - no exploit involved.

    Google has confirmed this and advises enabling 2-Step Verification or passkeys.

    Credential security remains the weakest link in most modern attacks.

    #CyberSecurity #APT37 #GoogleFindHub #ThreatIntel #AndroidSecurity #InfoSec #MalwareAnalysis #Kimsuky #TechNadu

  15. ScarCruft (APT37) is running Operation HanKook Phantom → phishing South Korean academics w/ RokRAT malware.
    🔹 LNK loaders + fileless PowerShell
    🔹 Exfil via Dropbox & GDrive
    🔹 Goal: espionage & persistence
    💬 Should academia ramp up defenses to enterprise SOC levels, or is that unrealistic?
    Follow @technadu for more threat intel.

    #CyberSecurity #APT37 #ScarCruft #RokRAT #Phishing #ThreatIntel

  16. Analysis of malicious HWP cases of 'APT37' group distributed through K messenger

    The report details a sophisticated APT attack targeting South Korea, utilizing spear-phishing techniques and malicious HWP files distributed through a popular Korean messenger service. The APT37 group exploited trust-based tactics, using compromised accounts to spread malware through group chats. The malicious files contained OLE objects that executed PowerShell commands and shellcode, ultimately deploying the RoKRAT malware. This file-less attack method allowed for information gathering and potential remote control of infected systems. The attackers used pCloud for data exfiltration and command-and-control communication. The report emphasizes the importance of endpoint detection and response (EDR) systems to combat such evolving threats.

    Pulse ID: 67a38d686710526e35f1ff4d
    Pulse Link: otx.alienvault.com/pulse/67a38
    Pulse Author: AlienVault
    Created: 2025-02-05 16:10:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APT37 #Cloud #CyberSecurity #EDR #Endpoint #EndpointDetectionandResponse #ICS #InfoSec #Korea #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Rust #ShellCode #SouthKorea #SpearPhishing #bot #pCloud #AlienVault

  17. Happy Friday everyone!

    It's always a good morning when you get news of some new MITRE ATT&CK Tactics, Techniques, or Sub-techniques! Nate Nelson highlights the new additions and discusses how #APT37 and #APT41 are adopting the techniques in recent attacks! Enjoy and Happy Hunting!

    DPRK Exploits 2 MITRE Sub-Techniques: Phantom DLL Hijacking, TCC Abuse
    darkreading.com/vulnerabilitie

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting! #readoftheday

  18. Took a look back at some of North Korea's #ROKRAT malware payload delivery mechanisms in my latest blog post:

    0x0v1.com/rearchive-rokrat-hwp

    #threatresearch #malware #APT37 #northkorea

  19. Happy Tuesday everyone!

    #APT37, aka #ScarCruft, is at it again! SentinelOne researchers noticed that they are targeting media organizations and others that are associated with North Korean affairs. The group leverages .LNK files, zip files, and phishing emails.

    I found this article most interesting because of the multiple types of file formats that were used, to include .bat and .dat files, involved in the campaign. They also use a custom backdoor known as #RokRat to aid in their attack. This is a great article and worth the time! Enjoy and Happy Hunting!

    Notable MITRE ATT&CK TTPs and Behaviors:
    TA0001 - Initial Access
    T1566.001 - Phishing: Spearphishing Attachment

    TA0002 - Execution
    T1059.001 - Command And Scripting Interpreter: Powershell
    T1204.001 - User Execution: Malicious Link

    sentinelone.com/labs/a-glimpse

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #gethunting

  20. NEW research on my blog!

    The evolution of North Korean threat group #APT37's Android spyware: #ROKRAT & #RambleOn

    In this research I perform a comparative analysis between ROKRAT & RambleOn, North Korean threat group APT37's Android malware.

    Link: 0x0v1.com/the-evolution-of-apt

    #threatintel #apt #reverseengineering #malware #spyware #northkorea

  21. In revisiting some old #APT37 samples, I wanted to take a look back at the #GOLDBACKDOOR dropper. Which actively targeted civil society & journalists based in South Korea.

    Here's in my reverse engineering analysis, I deep dive into this older malware campaign by the North Korean threat group.

    This is part of my project REarchive, where I look at historic APT campaigns that haven't been covered much publicly. Read here:
    0x0v1.com/rearchive-goldbackdo

    #malware #APT #northkorea #threatintel #reverseengineering

  22. b95cfde957c390a37371c6b36c2a2b0d986e2d9576e4fcb764e6e3452d307e23
    #apt37 #apt #threatintel

  23. Die vom nordkoreanischen Staat gesponserte Hackergruppe #ScarCruft (#APT37) hat die IT-Infrastruktur und den E-Mail-Server von NPO Mashinostroyeniya gehackt.

    NPO Mashinostroyeniya ist ein russischer Konstrukteur und Hersteller von Orbitalfahrzeugen, Raumfahrzeugen und taktischen Verteidigungs- und Angriffsraketen, die von der russischen und indischen Armee eingesetzt werden.

    #hack #russland #nordkorea #Opencarrot #windows

    bleepingcomputer.com/news/secu

    golem.de/news/angriff-aus-nord

  24. Just uploaded my #APT37 #ROKRAT shellcode decrypter script to my github. Hope this helps malware researchers out there

    github.com/0x0v1/MalwareRETool

  25. I just published a script that will assist malware researchers looking at #APT37's #ROKRAT to decode the PS reflection portion of the loader phase. It gives analysts the option to pull shellcode from the payload delivery host quickly for timely analysis.

    github.com/0x0v1/MalwareRETool

    I will later publish a script to deencrypt the shellcode for analysis - just need to clean a few things up in it.

  26. Happy Tuesday everyone! #APT37 is the topic of today's #readoftheday, specifically ThreatMon takes a deep-dive into the #RokRat malware, which is a remote access trojan (RAT). Enjoy and Happy Hunting!

    Link to article in the comments!

    ***AS usual I am going to leave one of the MITRE ATT&CK blank. I would like to see if any of you that see this can help FILL in that blank! If so, leave your thoughts in the comments OR send me a DM!***

    Notable MITRE ATT&CK TTPs:
    TA0007 - Discovery
    T1087 - Account Discovery
    T1083 - File and Directory Discovery
    T1018 - Remote System Discovery
    T1082 - System Information Discovery

    TA0009 - Collection
    T[What technique covers the threat actor capturing information under the TEMP folder?] - Good luck!

    TA0011 - Command And Control
    T1071.001 - Application Layer Protocol: Web Protocols

    TA0002 - Execution
    T1059.003 - Command and Scripting Interpreter: Windows Command Shell

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting

Share
Share on Mastodon

Enter the server where you have an account.