logo

APT37__2023__Ahnlab_HWP-Malware-Steganography-ScarCruft_02-21-2023.pdf

ID: 52342faf-d817-4bb8-8d16-0333d57eaf3a

STIX ID: report--52342faf-d817-4bb8-8d16-0333d57eaf3a

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2023-03-01

Last Modified Date: 2023-03-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AhnLab ASEC reports that the RedEyes (APT37/ScarCruft) group targeted individuals in Korea by embedding shellcode in a malicious HWP (EPS) document (CVE-2017-8291), which downloads a steganography-embedded image containing a XOR-encoded PE loader; that loader executes a file that fetches and injects M2RAT into explorer.exe, establishes persistence via a Run-key invoking PowerShell/mshta, and performs command-and-control, regular screenshots, keylogging, and exfiltration (including mobile-phone data) using shared-memory based C2 and encoded registry-stored identifiers — the report includes technical TTPs and multiple IOCs.