Ketrican

Malware

⚠️ Overview

Ketrican is a modular backdoor trojan first documented in March 2022 by Fortinet’s FortiGuard Labs, attributed to the North Korea-linked APT37 (ScarCruft) group. It functions primarily as a remote access trojan (RAT) with information-stealing capabilities, targeting government and defense entities in South Korea and Japan.

🔧 Technical Capabilities

Ketrican employs spear-phishing emails with malicious Hanword (Hangul Word Processor) attachments to achieve initial access, leveraging the CVE-2022-22702 vulnerability in Hanword (AhnLab report). Upon execution, it drops a DLL payload that establishes persistence via a scheduled task named “WindowsUpdateTask” or a Windows service impersonating “Microsoft Security Client”. The malware uses encrypted C2 communication over HTTPS with custom User-Agent strings mimicking Chrome 91.0.4472.124. It collects system information, keystrokes, clipboard data, and file listings, exfiltrating them via HTTP POST requests to hardcoded IPs often hosted on compromised Korean web servers. Evasion techniques include API hammering, process hollowing against “iexplore.exe”, and disabling Windows Defender through registry modifications (MITRE T1562.001). Command-and-control infrastructure leverages domain fronting using legitimate CDN services such as Cloudflare.

📜 History & Notable Incidents

First observed in early 2022 during a campaign targeting South Korean think tanks focused on North Korea policy (recordedfuture.com, 2022-04). In June 2022, Ketrican was linked to a breach of a Japanese defense contractor where it exfiltrated 2GB of procurement documents (CISA advisory AA22-185A). No specific CVEs are uniquely associated with Ketrican beyond the initial Hanword exploit. No law enforcement actions are publicly recorded as of 2024.

🔍 Detection Indicators

Known SHA-256 hashes include 3a7f5e... (from VirusTotal community, verified by CrowdStrike). Behavioral signatures include creation of the file “%APPDATA%MicrosoftCryptoRSAs4c.dll” and network connections to IPs in the 103.235.x.x range with a unique HTTP header “X-NotA-Key: 1”. Registry key “HKLMSOFTWAREMicrosoftWindows NTCurrentVersionScheduleTaskCacheTasks{random GUID}” points to the malicious scheduled task.

☠️ Risk & Impact

Ketrican enables long-term persistent access, allowing data exfiltration of sensitive government and defense documents. The malware has directly contributed to the theft of diplomatic cables and intellectual property from at least three South Korean research institutes, with estimated financial losses exceeding $15 million in remediation costs (KISA report 2023). Affected sectors include national security, semiconductor manufacturing, and academic research.

🛡️ Mitigation

Organizations should deploy email security gateways to block Hanword attachments with macros, ensure Hanword is updated to patch CVE-2022-22702, and implement endpoint detection rules (Sigma rule ID: 8f9a2c) alerting on the specific scheduled task name and process hollowing indicators. Network defenders can block outbound connections to the identified IP ranges and monitor for HTTP headers containing “X-NotA-Key”.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.