ScarCruft Uses RokRAT Malware in Operation HanKook Phantom Targeting South Korean Academics
Researchers studying cybersecurity have uncovered a new phishing effort used to spread the malware RokRAT by ScarCruft (also known as APT37), a hacker collective with ties to North Korea.
Seqrite Labs has given the activity the codename Operation HanKook Phantom and stated that the attacks seem to target people connected to the National Intelligence Research Association, including as researchers, academics, and former government officials.
According to a paper released last week by security researcher Dixit Panchal, the attackers most likely want to perform espionage, create persistence, or steal confidential data.
A spear-phishing email with a bait for the National Intelligence study Society Newsletter—Issue 52, a periodic newsletter published by a South Korean study group conce...

