logo

ScarCruft (APT37) active in South Korea.pdf

ID: 7349173f-e5ae-4c4b-9d5d-1f902fa09851

STIX ID: report--7349173f-e5ae-4c4b-9d5d-1f902fa09851

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2023-02-06

Last Modified Date: 2023-02-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This KISC presentation documents ScarCruft (APT37/Ricochet Chollima) targeted espionage activity against Korean-focused victims, describing the infection chain (phishing → decoy documents/macros → malicious scripts → Chinotto/Golang malware), detailed TTPs (DLL side-loading, BITSAdmin, VNC/UltraVNC, Ably channels), C2 artifacts and exfiltration methods, plus IOCs and a Defend Forward incident response process for monitoring, takedown and detection rule development.