North Korean hacking group RedEyes utilizes a new info-stealer called “FadeStealer”

With the ever-increasing threat of cyberattacks from various state-sponsored hacking groups, security researchers have identified a new info-stealer being used by the North Korean hacking group RedEyes. The group, also known as APT37, ScarCruft, and Reaper, has been active for nearly a decade and is affiliated with North Korea’s Ministry of State Security (MSS).

New Info-Stealer “FadeStealer”

AhnLab Security, a South Korean cybersecurity company, recently identified a new info-stealer being used by the North Korean hacking group RedEyes. Dubbed “FadeStealer,” this malware has exceptional features that allow threat actors to eavesdrop and capture audio through victims’ microphones. This new capability adds to the already extensive set of tools RedEyes employs for cyber espionage attacks.

Active since 2012, RedEyes is believed to be a state-sponsored APT group affiliated with North Korea’s Ministry of State Security (MSS). The group has been implicated in numerous cyber espionage attacks aligned with North Korea’s interests. Its focus areas include North Korean traitors and EU-based organizations.

Reported Incident

According to Cyber Security News, RedEyes recently carried out another cyber espionage attack. The group has been known for their long-standing involvement in cyber espionage attacks and this particular incident is believed to align with North Korea’s interests. The report did not disclose the targeted organization or the specifics of the attack.

The first breach in this particular cyber espionage attack was executed by the threat actor through the use of a CHM file. The file was probably part of a phishing email campaign that urged people to open it to obtain a document password, which ultimately infected their Windows computer with malware.

Backdoor Deployment

Later phases of the attack involved the deployment of an additional GoLang backdoor through another backdoor that was initially breached. This backdoor serves the purpose of allowing the threat actor access to the victim’s system and providing persistence for future attacks.

The North Korean hacking group utilized DLL sideloading, a technique that involves injecting malicious code into an already running legitimate process. In this case, the attackers used the legitimate Internet Explorer process called “ieinstal.exe,” and with the help of DLL sideloading, they injected the FadeStealer malware after installation.

Multiple threat actors utilize CHM files. While RedEyes (also known as APT37, ScarCruft, and Reaper) is one of the North Korean threat actors to use CHM files to distribute malware, it is not alone. Other North Korean threat actors also use this method. This technique is particularly effective, as CHM files are often considered trusted files and are not usually flagged by antivirus software.

As state-sponsored hacking groups continue to develop new and more potent malware, it is critical for organizations to stay vigilant and up-to-date on the latest threats. The deployment of unique malware like FadeStealer by RedEyes highlights the group’s growing capabilities and emphasizes the need for robust cybersecurity measures to keep sensitive data and systems secure.

Explore more

Effective Email Automation Strategies Drive Business Growth

The digital landscape is currently witnessing a silent revolution where the most successful marketing teams have stopped competing for attention through volume and started winning through surgical precision. While many organizations continue to struggle with the exhausting cycle of manual campaign creation, a sophisticated subset of the market has mastered the art of “set it and forget it” revenue generation.

How Can Modern Email Marketing Drive Exceptional ROI?

Every second, millions of digital messages flood into global inboxes, yet only a tiny fraction of these communications actually manage to convert a passive reader into a loyal, high-value customer. While the average marketer often points to a return of thirty-six dollars for every dollar spent as a benchmark of success, this figure represents a mere starting point for organizations

Modern Tactics Drive High-Performance Email Marketing

The sheer volume of digital correspondence flooding the modern consumer’s primary inbox has reached a point where generic messaging is no longer merely ignored but actively penalized by sophisticated filtering algorithms. As the global email ecosystem navigates a staggering daily volume of nearly 400 billion messages, the traditional “spray and pray” methodology has transformed from a sub-optimal tactic into a

How Will AI-Native 6G Networks Change Global Connectivity?

Global telecommunications are currently undergoing a profound metamorphosis that transcends simple speed upgrades, aiming instead to weave an intelligent fabric directly into the world’s physical reality. While the transition from 4G to 5G was defined by raw speed and reduced latency, the move toward 6G represents a fundamental departure from traditional telecommunications. The industry is moving toward a reality where

How Is AI Redefining the Future of 6G and Telecom Security?

The sheer velocity of data surging through modern global telecommunications has already pushed traditional human-centric management systems toward a breaking point that demands a complete architectural overhaul. While the industry previously celebrated the arrival of high-speed mobile broadband, the current shift represents a fundamental departure from hardware-heavy engineering toward a software-defined, intelligent ecosystem. This evolution marks a pivotal moment where