APT37__2019__ScarCruft_continues_to_evolve_introduces_Bluetooth_harvester_Securelist.pdf
ID: 08d777a0-cbc9-4d50-ad72-509e5a872f77
STIX ID: report--08d777a0-cbc9-4d50-ad72-509e5a872f77
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-05-14
Last Modified Date: 2019-05-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ScarCruft (ScarCraft) is a Korean-speaking, likely state-sponsored APT that conducts multi-stage infections—using spear-phishing/SWC, UAC bypass (CVE-2018-8120/UACME), steganographic downloaders—to deploy a cloud-based ROKRAT backdoor and an uncommon Bluetooth device harvester; the report details victimology (diplomatic and investment targets), overlaps with DarkHotel, and provides numerous IOCs (file hashes, URLs, domains and IPs).
