ScarCruft | Attackers Gather Strategic Intelligence and Target Cybersecurity Professionals
ID: d445d124-38a4-5d42-9d72-7bd865be64f2
STIX ID: report--d445d124-38a4-5d42-9d72-7bd865be64f2
Threat Score
Date Published: 2024-01-22
Date Updated: 2026-07-27
Author: Aleksandar Milenkoski & Tom Hegel
...
...
SentinelLABS details a ScarCruft (APT37/InkySquid) campaign targeting North Korea-focused researchers and media using oversized LNK decoys and multi-stage PowerShell/shellcode to deploy the RokRAT backdoor; the report provides technical analysis of infection chains, decoy documents, testing artifacts, and extensive IOCs (file hashes, domains, IPs, and email addresses) to aid detection and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
