logo

SAS2019 Presentation

ID: cc76b8d6-368e-48d5-bd64-7c330d9d36bc

STIX ID: report--cc76b8d6-368e-48d5-bd64-7c330d9d36bc

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2020-02-06

Last Modified Date: 2020-02-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This presentation analyzes ScarCruft (APT37), a Korean-speaking, state-linked APT that uses spearphishing, weaponized HWP/Word files, public and zero-day exploits (e.g., CVE-2016-4171, CVE-2017-11182, CVE-2018-8120) and web waterhole attacks to deliver custom tooling including a cloud-based backdoor (ROKRAT) that exfiltrates data via cloud services (Box, Dropbox, Pcloud, Yandex); it includes TTPs, C2 details, sample IOCs (IPs/domains, payload patterns), victimology across the Korean-peninsula interest sphere, and operational comparisons with other groups like DarkHotel.