logo

ScarCruft Abuses Legitimate Cloud Services for C2 and OLE-based Chain to Drop Malware

ID: 683c46e1-dcd9-5f2a-bdc2-4b20ab266550

STIX ID: report--683c46e1-dcd9-5f2a-bdc2-4b20ab266550

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ScarCruft, a North Korean–backed APT, has evolved its intrusion methods by embedding malicious OLE objects in HWP documents to deploy the ROKRAT remote access trojan; the campaign leverages DLL side‑loading (examples: mpr.dll, credui.dll), in‑memory execution with a 0x29 XOR decryption, and abused commercial cloud services (pCloud, Yandex) for C2, with technical markers (ROR13 resolving and steganography-hosted shellcode) that tie these incidents to the group’s historical operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.