logo

APT37__2019__ScarCruft_continues_to_evolve_introduces_Bluetooth_harvester_Securelist.pdf

ID: 08d777a0-cbc9-4d50-ad72-509e5a872f77

STIX ID: report--08d777a0-cbc9-4d50-ad72-509e5a872f77

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-05-14

Last Modified Date: 2019-05-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ScarCruft (ScarCraft) is a Korean-speaking, likely state-sponsored APT that conducts multi-stage infections—using spear-phishing/SWC, UAC bypass (CVE-2018-8120/UACME), steganographic downloaders—to deploy a cloud-based ROKRAT backdoor and an uncommon Bluetooth device harvester; the report details victimology (diplomatic and investment targets), overlaps with DarkHotel, and provides numerous IOCs (file hashes, URLs, domains and IPs).