Kim Yo Jong

  • ScarCruft Uses RokRAT in HanKook Phantom Campaign Targeting South Korea

    , , ,

    Researchers have uncovered a targeted phishing campaign by North Korea-linked ScarCruft (APT37), dubbed Operation HanKook Phantom, delivering RokRAT to South Korean academics, former officials, and researchers via a manipulated LNK attack chain and PowerShell-based payloads, with exfiltration to multiple cloud services and a willingness to use decoy documents tied to high-profile statements.

    ScarCruft Uses RokRAT in HanKook Phantom Campaign Targeting South Korea