The advanced persistent threat (APT) group ScarCruft from North Korea uses weaponized Microsoft Compiled HTML Help (CHM) files to infect targeted machines with additional malware.

Numerous reports from AhnLab Security Emergency response Center (ASEC), SEKOIA.IO , and Zscaler highlight that these efforts to evade detection demonstrate the group's ongoing efforts to refine its strategies .
"The team is constantly evolving its tools, techniques, and processes while experimenting with new file formats and methods to bypass security vendors," Zscaler researchers Sudeep Singh and Naveen Selvan said in a new analysis published Tuesday.
The ScarCruft group, also known by the other aliases APT37, Reaper, RedEyes, and Ricochet Chollima, has been particularly active since early 2021. This malicious group is known for its espionage operations against South Korean entities, which have been ongoing since 2012.
Last month, ASEC uncovered a campaign that used HWP files that exploited a security flaw in Hangul word processing software to deploy a backdoor referred to as M2RAT.
Recent discoveries indicate that the malicious actor is also using other file types, such as CHM, HTA, LNK, XLL, and macro-based Microsoft Office documents, in spear-phishing against South Korean.

Infection chains are often used to deceptively display a fake file and install a newer version of Chinotto, which is a PowerShell-based implant suitable for executing commands sent from the server and transferring confidential data.
See also: Fake ChatGPT Chrome extension hacks Facebook accounts
Chinotto revolutionizes the way information can be collected and secured, with cutting-edge features such as automatic screenshot taking every five seconds and keystroke logging. These details are compressed into a ZIP file and then sent to an external server for added security.
Information about ScarCruft's various attack vectors comes from a GitHub repository maintained by the adversary group to host malicious payloads since October 2020.
"The threat actor was able to maintain a GitHub repository, frequently deploying malicious payloads for over two years without being detected or removed," Zscaler researchers said.
In addition to spreading malware, the ScarCruft group is also known to host credential phishing websites targeting multiple email and cloud services, including Naver, iCloud, Kakao, Mail.ru, and 163.com.
See also: Dole: Ransomware attack led to data breach

It is currently uncertain how victims gain access to these pages, leading to speculation that they may be contained in iframes on websites managed by the attacker or sent as HTML attachments via email.
Also discovered by SEKOIA.IO is a piece of malware called AblyGo, a backdoor written in Go that uses the messaging to receive commands.
See also: New credit card theft hacking campaign detected
The use of CHM files to “smuggle malware” appears to be catching on with other groups linked to North Korea, with ASEC uncovering a phishing campaign orchestrated by Kimsuky to distribute a backdoor responsible for collecting clipboard data and logging keystrokes.
Information source: thehackernews.com
