
A North Korean threat actor known as ScarCruft uses a previously undocumented information-stealing malware with eavesdropping capabilities and a backdoor developed using Golang that exploits the Ably real-time messaging service. is observed.
“The threat actor sent commands through a Golang backdoor using the Ably service,” said the AhnLab Security Emergency Response Center (ASEC) in a technical report. “The API key value required for command communication has been saved in the GitHub repository.”
ScarCruft is a state aid organization with ties to the North Korean Ministry of State Security (MSS). Known to be active since at least 2012.

The attack chain launched by this group requires the use of spear phishing lures to deliver RokRAT, but also leverages various other custom tools to gather sensitive information.
In the most recent intrusion detected by ASEC, the email contained a Microsoft Compiled HTML Help (.CHM) file, and the technique was first reported in March 2023. Once clicked, it connects to a remote server and downloads PowerShell malware known as Chinotto. .
In addition to persistence settings, Chinotto gets an additional payload containing a backdoor codenamed AblyGo (a.k.a. Kaspersky’s SidLevel) that abuses Ably for command and control.

This is not the end. AblyGo is a vector for eventual execution of an information-stealing malware called FadeStealer, which is capable of taking screenshots, collecting data from removable media and smartphones, recording keystrokes, recording microphones, and more. will be used.
“The Red Eyes Group has targeted specific individuals, including North Korean defectors, human rights activists, and university professors,” ASEC said. “Their main focus is information theft.”
“In South Korea, unauthorized eavesdropping on individuals is considered a violation of privacy and is strictly regulated by relevant laws. gone.”
🔐 Mastering API Security: Understanding Your True Attack Surface
Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!
join the session
CHM files are also used by other North Korea-affiliated groups such as Kimsuky, and SentinelOne published a recent campaign utilizing the file format to provide a reconnaissance tool called RandomQuery.
In a series of new attacks discovered by ASEC, CHM files are configured to drop BAT files, which are used to download the next stage of malware and exfiltrate user information from compromised hosts. increase.
U.S. and South Korean intelligence agencies advise that spear phishing, Kimski’s preferred initial access method for more than a decade, is typically preceded by extensive research and careful preparation.
The findings suggest that the Lazarus Group has actively exploited security flaws in software such as INISAFE CrossWeb EX, MagicLine4NX, TCO!Stream, and VestCert, which are widely used in South Korea to infiltrate enterprises and deploy malware. It is also based on the fact that there is