ScarCruft (APT37) active in South Korea.pdf
ID: 7349173f-e5ae-4c4b-9d5d-1f902fa09851
STIX ID: report--7349173f-e5ae-4c4b-9d5d-1f902fa09851
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2023-02-06
Last Modified Date: 2023-02-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This KISC presentation documents ScarCruft (APT37/Ricochet Chollima) targeted espionage activity against Korean-focused victims, describing the infection chain (phishing → decoy documents/macros → malicious scripts → Chinotto/Golang malware), detailed TTPs (DLL side-loading, BITSAdmin, VNC/UltraVNC, Ably channels), C2 artifacts and exfiltration methods, plus IOCs and a Defend Forward incident response process for monitoring, takedown and detection rule development.
