APT37__2023__Ahnlab_HWP-Malware-Steganography-ScarCruft_02-21-2023.pdf
ID: 52342faf-d817-4bb8-8d16-0333d57eaf3a
STIX ID: report--52342faf-d817-4bb8-8d16-0333d57eaf3a
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2023-03-01
Last Modified Date: 2023-03-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AhnLab ASEC reports that the RedEyes (APT37/ScarCruft) group targeted individuals in Korea by embedding shellcode in a malicious HWP (EPS) document (CVE-2017-8291), which downloads a steganography-embedded image containing a XOR-encoded PE loader; that loader executes a file that fetches and injects M2RAT into explorer.exe, establishes persistence via a Run-key invoking PowerShell/mshta, and performs command-and-control, regular screenshots, keylogging, and exfiltration (including mobile-phone data) using shared-memory based C2 and encoded registry-stored identifiers — the report includes technical TTPs and multiple IOCs.
