ScarCruft Exploits Trusted Cloud Services and OLE Documents to Deliver Malware
ID: 824bc8ca-42a1-5274-b2a6-f2d85fa1bcad
STIX ID: report--824bc8ca-42a1-5274-b2a6-f2d85fa1bcad
Feed Name: GBHackers
ScarCruft has evolved from LNK/BAT-based DROKLINK tactics to embedding OLE-based droppers inside HWP documents to load ROKRAT in memory; researchers observed three variants (DLL side-loading, cloud downloader retrieving steganographic shellcode, and an in-memory executor) that use pCloud and Yandex APIs for C2 and data disguise, increasing evasion and forensic difficulty. Organizations should treat unsolicited HWP files with extreme caution and apply policies to detect or block abnormal OLE objects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
