The North Korea-linked ScarCruft group, also tracked as RedEyes and APT37, used multiple lure themes and file formats to target South Korean users with espionage malware. In one campaign, attackers weaponized Hangul Word Processor documents with the EPS flaw CVE-2017-8291, embedding malicious EPS content that executed code, dropped scripts, downloaded additional payloads, and launched malware through rundll32. A later AhnLab investigation found the group hiding an encoded PE payload inside a downloaded JPEG via steganography, then decoding a loader that established persistence through a Run key and used PowerShell and mshta before injecting a newly identified backdoor, M2RAT, into explorer.exe.
ScarCruft also shifted to CHM lures tied to the Fukushima wastewater issue, using social engineering to trigger JavaScript and an encoded PowerShell backdoor that could persist, receive commands, steal files, and manipulate the registry and scheduled tasks. Researchers said M2RAT expands the group’s collection capabilities with keylogging, screen capture, process control, file theft, and USB or document exfiltration, while earlier reporting also documented ScarCruft’s evolving tooling, including a Bluetooth harvester. The activity shows a sustained pattern of adapting delivery methods while maintaining a focus on intelligence collection from carefully selected victims in South Korea.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
ASEC reported renewed distribution of a malicious CHM file attributed to RedEyes that used the Fukushima contaminated water discharge issue as a lure for Korean users. The newer variant established persistence through a Windows Run key instead of directly launching mshta from hh.exe, and ASEC said its persistence-stage command matched the M2RAT attack chain.
ASEC publicly reported the January RedEyes/ScarCruft campaign and attributed it based on steganography use and persistence similarities to prior ScarCruft activity. The report also introduced M2RAT as a distinct backdoor differing from Chinotto in command handling and exfiltration behavior.
AhnLab ASD detected exploitation activity involving the malicious HWP file "양식.hwp". Opening the document triggered shellcode that downloaded a JPEG from attacker infrastructure and extracted an encoded PE payload via steganography.
In the January campaign, the decoded loader established Run-key persistence, launched PowerShell and mshta, downloaded an additional backdoor, and injected it into explorer.exe. ASEC identified this newly observed malware as M2RAT and described capabilities including keylogging, screen capture, process control, file theft, and USB/document exfiltration.
ASEC said RedEyes/ScarCruft distributed malware in January using a malicious HWP document named "양식.hwp" that exploited the Hangul EPS vulnerability CVE-2017-8291. The campaign targeted specific individuals in South Korea, likely including users of older Hangul versions that still supported EPS processing.
In the active 2020 campaign, an embedded EPS object in the HWP file exploited CVE-2017-8291, dropped a VBS script, downloaded an encoded payload, decoded it into a DLL, and executed it with rundll32 using the InstallSafari export. The malware then contacted mokawafm.com to send system information and receive additional data.
ASEC reported an increase in malicious Hangul Word Processor documents exploiting the EPS flaw CVE-2017-8291 beginning in April 2020. The campaign used real-estate investment themed phishing emails to lure recipients into opening weaponized HWP attachments.
Kaspersky published research on ScarCruft's evolving malware, including a Bluetooth harvester capability. This prior reporting was later cited by ASEC as context for RedEyes/ScarCruft tradecraft similarities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.