The North Korean hacking group APT37 has developed a new malicious software “FadeStealer” for stealing information that includes a “eavesdropping” function, which allows the threat actor to monitor and record from the victims' microphones.
The APT37, also known as StarCruft, Reaper or RedEyes, is believed to be a state‑sponsored hacking group with a long history of conducting cyber‑espionage attacks, aligned with the interests of North Korea. These attacks target North Korean dissidents, educational institutions and organizations based in the EU.
In the past, hackers have been known to use custom malware, such as “Dolphin” and “M2RAT,” to execute commands and steal data, credentials , and screenshots from Windows devices and even connected mobile phones.
See also: NoName057 hacking group attacked ports in the Netherlands and Belgium

See also: AnyConnect: PoC released for Cisco bug that grants SYSTEM privileges
It starts with a CHM file
In a new report from AhnLab Security Emergency Response Center (ASEC), researchers provide information on new custom malware dubbed “AblyGo backdoor” and “FadeStealer” that threat actors are using in cyberespionage.
The malware is believed to have been delivered using phishing emails with attached files that contained Word and Hangul Word Processor documents (.docx and .hwp files) that are password-protected and a Windows CHM file “password.chm”.
ASEV believes that electronic “phishing” messages guide the recipient to open the CHM file in order to obtain the password for the documents, which then initiates the infection process on the Windows device.
Once the CHM file is opened, the purported password for opening the document will be displayed, but it will also silently download and execute a remote PowerShell script, which has backdoor capabilities and is programmed to auto-start with Windows.
This PowerShell backdoor communicates with the attacker’s command and control servers and executes any commands the attackers send.
The backdoor is used to develop an additional GoLang backdoor, which is used in later stages of the attack for privilege escalation, data theft, and delivery of further malicious software.
This new backdoor is called the “AblyGo backdoor,” as it uses the Ably platform, an API service that allows developers to build real-time functionality and information delivery into their applications
Threat actors use ABLY as a command and control platform to send commands encoded with base64 to the backdoor, in order to execute them and then receive any output, which the threat actors retrieve later.
As this is a legitimate platform, it is likely to be used by threat actors to bypass network monitoring and security software.
ASE-C gained access to the Ably API key used by the backdoor and was able to observe some of the commands issued by the attackers. These commands illustrated how the hackers used the backdoor to list files in a directory, rename a fake .jpg file to an .exe file, and then execute it.
However, it is technically possible for the threat actor to send any command it wishes to execute.

See also: iOttie: Announced data breach
FadeStealer monitors your device
Ultimately, the backdoors develop a final payload in the form of “FadeStealer”, a malicious software that can steal information from Windows devices.
Once installed, FadeStealer is injected using DLL sideloading into the legitimate Internet Explorer process 'ieinstall.exe' and begins stealing data from the device and saving it to RAR files every 30 minutes.
The data includes screenshots, logged keystrokes, files collected from connected smartphones and removable devices. The malware also has the capability to record audio from a connected microphone, allowing threat actors to monitor conversations.
These data are collected in the following folders %Temp%:

Threat actors can then analyze the collected data to steal sensitive information for use by the North Korean government or to carry out further attacks.
APT37 is not the only North Korean threat actor that uses CHM files for malware development.
ASEK reported today that the state-backed hacking group Kimsuky is using CHM files in phishing attacks to deploy malicious scripts that steal user information and install additional malware.
Information source: bleepingcomputer.com
