logo

ScarCruft Exploits Trusted Cloud Services and OLE Documents to Deliver Malware

ID: 824bc8ca-42a1-5274-b2a6-f2d85fa1bcad

STIX ID: report--824bc8ca-42a1-5274-b2a6-f2d85fa1bcad

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ScarCruft has evolved from LNK/BAT-based DROKLINK tactics to embedding OLE-based droppers inside HWP documents to load ROKRAT in memory; researchers observed three variants (DLL side-loading, cloud downloader retrieving steganographic shellcode, and an in-memory executor) that use pCloud and Yandex APIs for C2 and data disguise, increasing evasion and forensic difficulty. Organizations should treat unsolicited HWP files with extreme caution and apply policies to detect or block abnormal OLE objects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.