logo

North Korea's ScarCruft Attackers Gear Up to Target Cybersecurity Pros

ID: de76700b-c156-50b8-9134-4edc2554b45c

STIX ID: report--de76700b-c156-50b8-9134-4edc2554b45c

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-01-22

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

SentinelLabs observed ScarCruft (APT37) conducting testing and refinement of LNK-based infection chains that use decoy research on another DPRK actor (Kimsuky) as a lure; weaponized samples deploy RokRAT backdoors and the activity appears aimed at stealing nonpublic threat intelligence and compromising security researchers and organizations for follow-on impersonation campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.