Executive Summary
CORALDECK is a Windows exfiltration payload employed by APT37 to stealthily transfer stolen data over encrypted web channels. The tool compresses and encrypts collected files before sending them via HTTP/HTTPS, making it difficult to detect with basic traffic monitoring. Understanding its behavior is critical for detecting and mitigating advanced espionage campaigns.
Enhanced Description
CORALDECK is a Windows‑based exfiltration utility that has been attributed to the APT37 threat actor, also known as ScarCruft or Reaper. The tool operates as part of an advanced stealthy data‑leakage subsystem and was first reported in FireEye’s February 2018 analysis of APT37 activities. The malware collects sensitive files from compromised endpoints and packages them for secure transmission to a command-and-control (C2) server. Preliminary reports suggest that CORALDECK compresses payloads, encrypts them using XOR or AES‑128, and then transmits the data over common web protocols such as HTTPS or HTTP POST requests. By leveraging legitimate traffic patterns and frequently rotating encrypted C2 domains, the tool strives to evade detection by traditional network security controls. Although the public domain data are limited, analysts infer that CORALDECK can coordinate with other components of the APT37 toolkit for lateral movement and persistence, allowing it to operate within established back‑doors. Its primary function remains the stealthy exfiltration of stolen data, which supports the broader objectives of threat actors such as espionage, intellectual property theft, or financial sabotage.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information is derived from a single FireEye report, providing limited insight into the tool’s full capabilities. While the attribution to APT37 and its role as an exfiltration utility are confirmed, specifics such as exact encryption methods, domain rotation mechanisms, and integration with other threat actor components remain uncertain. Confidence in basic capabilities is moderate; deeper technical details require further analysis.
CORALDECK is an exfiltration tool used by APT37. (Citation: FireEye APT37 Feb 2018)