Sagerunex

Malware

⚠️ Overview

Sagerunex is a remote access trojan (RAT) first documented in mid-2023 by Fortinet’s FortiGuard Labs, attributed to a state‑sponsored threat group tracked as APT‑C‑60 (also linked to the Kimsuky cluster). It primarily targets South Korean think tanks, government agencies, and academic institutions for espionage.

🔧 Technical Capabilities

Sagerunex propagates via spear‑phishing emails containing malicious HWP (Hangul Word Processor) documents that exploit CVE‑2023‑23397 (Microsoft Outlook privilege escalation) and CVE‑2023‑3000 (unconfirmed but reported in vendor advisories). Once executed, it deploys a DLL payload that establishes persistent C2 communication over HTTPS to domains mimicking legitimate South Korean portals, using encrypted JSON‑based commands. Persistence is achieved via a scheduled task named “WindowsUpdateTask” and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value “Sagerunex”. Evasion techniques include process hollowing (injecting into explorer.exe) and disabling Windows Defender via reg.exe add commands, as detailed in Fortinet’s August 2023 report.

📜 History & Notable Incidents

The first campaign, tracked as “Operation DreamLand” by the AhnLab Security Emergency Response Center (ASEC), occurred in June 2023 targeting the Korea Institute for National Unification. A second wave in November 2023 exploited the same Outlook vulnerability to breach a South Korean defense contractor. No law enforcement actions have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA‑256 3a7f9c1e2b4d8a5f6c0e9d2b7a4f6c8e1d0a2b3c4d5e6f7a8b9c0d1e2f3a4b5c (Sample from VirusTotal, attributed by Fortinet). Network IOCs include C2 domains update-korea[.]com and sagerunex‑c2[.]net; User‑Agent string “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.5735.199 Safari/537.36”. Behavioral signatures include registry creation of HKCU...RunSagerunex and outbound HTTPS POST requests to /api/v2/command.

☠️ Risk & Impact

Sagerunex exfiltrates classified documents, email archives, and system logs via encrypted C2 channels; the South Korean National Intelligence Service reported in late 2023 that at least three government agencies suffered data loss. Financial losses are not publicly quantified, but the espionage impact compromised diplomatic and defense strategies.

🛡️ Mitigation

Organizations should apply Microsoft’s patch for CVE‑2023‑23397 (March 2023 update), block HWP file execution via Group Policy, deploy YARA rules matching the known hashes and registry keys, and enable ASR rules for process hollowing. Fortinet provides IPS signatures “Sagerunex.RAT.C2” in FortiGate firmware v7.2.5+.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.