Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
North Korean hackers dump RokRAT malware on South Korea's digital infra, target Internet Explorer
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • North Korean hackers dump RokRAT malware on South Korea's digital infra, target Internet Explorer

North Korean hackers dump RokRAT malware on South Korea's digital infra, target Internet Explorer

FP Staff • December 9, 2024, 11:28:55 IST
Whatsapp Facebook Twitter

Known for their sophisticated attacks, ScarCruft, also called APT37 or RedEyes, has targeted South Korean digital infrastructure, with a focus on human rights activists, defectors, and political entities in Europe

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
North Korean hackers dump RokRAT malware on South Korea's digital infra, target Internet Explorer
The hackers compromised the server of a South Korean advertising agency, distributing malicious toast ads via a popular but unnamed free software used extensively in the country. These ads carried a hidden iframe triggering a JavaScript file. Image Credit: Reuters

North Korea’s state-linked hacker group, ScarCruft, has launched a major cyber-espionage campaign against South Korea, exploiting a flaw in Internet Explorer to deploy the RokRAT malware. Known for their sophisticated attacks, ScarCruft, also called APT37 or RedEyes, has targeted South Korean digital infrastructure, with a focus on human rights activists, defectors, and political entities in Europe.

This latest campaign, intriguingly named “Code on Toast,” has raised serious concerns about vulnerabilities in software still embedded within widely used systems, even after Internet Explorer’s retirement.

STORY CONTINUES BELOW THIS AD

Internet Explorer exploited via innovative “Toast Ads”

ScarCruft’s attack hinges on a clever exploitation of an Internet Explorer zero-day vulnerability, tracked as CVE-2024-38178, with a severity score of 7.5. The group leveraged toast notifications—typically harmless pop-up ads from antivirus software or utility programs—to silently deliver malware through a zero-click infection method.

The hackers compromised the server of a South Korean advertising agency, distributing malicious toast ads via a popular but unnamed free software used extensively in the country. These ads carried a hidden iframe triggering a JavaScript file, which exploited the Internet Explorer vulnerability in the JScript9.dll file of its Chakra engine. Despite Internet Explorer being officially retired in 2022, its lingering components in Windows systems made it a prime target for this attack.

More from Tech
How ChatGPT is becoming everyone’s BFF and why that’s dangerous How ChatGPT is becoming everyone’s BFF and why that’s dangerous America ready for self-driving cars, but it has a legal problem America ready for self-driving cars, but it has a legal problem

The malicious code injected into systems was alarmingly sophisticated, bypassing earlier Microsoft security patches with additional layers of exploit. This campaign mirrored ScarCruft’s previous use of a similar vulnerability in 2022 but added new tricks to evade detection.

RokRAT malware and its potent threats

Once the vulnerability was exploited, ScarCruft deployed RokRAT malware to infected systems. This malware is a powerful tool for surveillance and data theft. It exfiltrates files with extensions like .doc, .xls, and .ppt to a Yandex cloud server every 30 minutes. Beyond file theft, RokRAT can record keystrokes, monitor clipboard activity, and take screenshots every three minutes, providing a complete surveillance package.

The infection process unfolds in four stages, with payloads hidden within the ‘explorer.exe’ process to escape antivirus detection. If security tools like Avast or Symantec are detected, the malware adapts by injecting into random executables from the Windows system folder. Persistence is ensured by placing the final payload in the startup folder, running at regular intervals to maintain control.

South Korea in a state of alarm

The use of such advanced techniques by ScarCruft highlights a growing threat to South Korea’s digital landscape.

Despite efforts to phase out outdated systems, vulnerabilities in legacy components like Internet Explorer remain a weak point. This campaign serves as a stark reminder for organisations to prioritise updates and maintain robust cybersecurity defences against increasingly sophisticated state-backed cyber threats.

Editor’s Picks
1
How North Korean hackers stole billions in crypto while posing as VCs, IT workers
How North Korean hackers stole billions in crypto while posing as VCs, IT workers
2
North Korea-backed hackers conduct espionage campaign against US, India and more, intel agencies warn
North Korea-backed hackers conduct espionage campaign against US, India and more, intel agencies warn
Tags
cybersecurity North Korea South Korea
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

America ready for self-driving cars, but it has a legal problem

America ready for self-driving cars, but it has a legal problem

US self-driving cars may soon ditch windshield wipers as the NHTSA plans to update regulations by 2026. State-level rules vary, complicating nationwide deployment. Liability and insurance models are also evolving with the technology.

More Impact Shorts

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV