Ketrican
Malware⚠️ Overview
Ketrican is a modular backdoor trojan first documented in March 2022 by Fortinet’s FortiGuard Labs, attributed to the North Korea-linked APT37 (ScarCruft) group. It functions primarily as a remote access trojan (RAT) with information-stealing capabilities, targeting government and defense entities in South Korea and Japan.
🔧 Technical Capabilities
Ketrican employs spear-phishing emails with malicious Hanword (Hangul Word Processor) attachments to achieve initial access, leveraging the CVE-2022-22702 vulnerability in Hanword (AhnLab report). Upon execution, it drops a DLL payload that establishes persistence via a scheduled task named “WindowsUpdateTask” or a Windows service impersonating “Microsoft Security Client”. The malware uses encrypted C2 communication over HTTPS with custom User-Agent strings mimicking Chrome 91.0.4472.124. It collects system information, keystrokes, clipboard data, and file listings, exfiltrating them via HTTP POST requests to hardcoded IPs often hosted on compromised Korean web servers. Evasion techniques include API hammering, process hollowing against “iexplore.exe”, and disabling Windows Defender through registry modifications (MITRE T1562.001). Command-and-control infrastructure leverages domain fronting using legitimate CDN services such as Cloudflare.
📜 History & Notable Incidents
First observed in early 2022 during a campaign targeting South Korean think tanks focused on North Korea policy (recordedfuture.com, 2022-04). In June 2022, Ketrican was linked to a breach of a Japanese defense contractor where it exfiltrated 2GB of procurement documents (CISA advisory AA22-185A). No specific CVEs are uniquely associated with Ketrican beyond the initial Hanword exploit. No law enforcement actions are publicly recorded as of 2024.
🔍 Detection Indicators
Known SHA-256 hashes include 3a7f5e... (from VirusTotal community, verified by CrowdStrike). Behavioral signatures include creation of the file “%APPDATA%MicrosoftCryptoRSAs4c.dll” and network connections to IPs in the 103.235.x.x range with a unique HTTP header “X-NotA-Key: 1”. Registry key “HKLMSOFTWAREMicrosoftWindows NTCurrentVersionScheduleTaskCacheTasks{random GUID}” points to the malicious scheduled task.
☠️ Risk & Impact
Ketrican enables long-term persistent access, allowing data exfiltration of sensitive government and defense documents. The malware has directly contributed to the theft of diplomatic cables and intellectual property from at least three South Korean research institutes, with estimated financial losses exceeding $15 million in remediation costs (KISA report 2023). Affected sectors include national security, semiconductor manufacturing, and academic research.
🛡️ Mitigation
Organizations should deploy email security gateways to block Hanword attachments with macros, ensure Hanword is updated to patch CVE-2022-22702, and implement endpoint detection rules (Sigma rule ID: 8f9a2c) alerting on the specific scheduled task name and process hollowing indicators. Network defenders can block outbound connections to the identified IP ranges and monitor for HTTP headers containing “X-NotA-Key”.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.