SAS2019 Presentation
ID: cc76b8d6-368e-48d5-bd64-7c330d9d36bc
STIX ID: report--cc76b8d6-368e-48d5-bd64-7c330d9d36bc
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2020-02-06
Last Modified Date: 2020-02-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This presentation analyzes ScarCruft (APT37), a Korean-speaking, state-linked APT that uses spearphishing, weaponized HWP/Word files, public and zero-day exploits (e.g., CVE-2016-4171, CVE-2017-11182, CVE-2018-8120) and web waterhole attacks to deliver custom tooling including a cloud-based backdoor (ROKRAT) that exfiltrates data via cloud services (Box, Dropbox, Pcloud, Yandex); it includes TTPs, C2 details, sample IOCs (IPs/domains, payload patterns), victimology across the Korean-peninsula interest sphere, and operational comparisons with other groups like DarkHotel.
