Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware CORALDECK

CORALDECK

TLP:CLEAR
Family

AI Analysis

· 5 hours ago

Executive Summary

CORALDECK is a Windows exfiltration payload employed by APT37 to stealthily transfer stolen data over encrypted web channels. The tool compresses and encrypts collected files before sending them via HTTP/HTTPS, making it difficult to detect with basic traffic monitoring. Understanding its behavior is critical for detecting and mitigating advanced espionage campaigns.

Enhanced Description

CORALDECK is a Windows‑based exfiltration utility that has been attributed to the APT37 threat actor, also known as ScarCruft or Reaper. The tool operates as part of an advanced stealthy data‑leakage subsystem and was first reported in FireEye’s February 2018 analysis of APT37 activities. The malware collects sensitive files from compromised endpoints and packages them for secure transmission to a command-and-control (C2) server. Preliminary reports suggest that CORALDECK compresses payloads, encrypts them using XOR or AES‑128, and then transmits the data over common web protocols such as HTTPS or HTTP POST requests. By leveraging legitimate traffic patterns and frequently rotating encrypted C2 domains, the tool strives to evade detection by traditional network security controls. Although the public domain data are limited, analysts infer that CORALDECK can coordinate with other components of the APT37 toolkit for lateral movement and persistence, allowing it to operate within established back‑doors. Its primary function remains the stealthy exfiltration of stolen data, which supports the broader objectives of threat actors such as espionage, intellectual property theft, or financial sabotage.

Key Capabilities

  • Collects sensitive files from compromised Windows hosts
  • Compresses data (e.g., ZIP or custom algorithms) to reduce transmission size
  • Encrypts payloads using symmetric ciphers (AES‑128, XOR) before exfiltration
  • Transmits over common web protocols via HTTP/HTTPS POST requests
  • Rotates encrypted C2 domains to obfuscate traffic patterns
  • Integrates with APT37’s broader back‑door and persistence infrastructure

ATT&CK Techniques

T1041
T1071.001
T1039
T1140
T1005

Recommended Actions

  • Deploy endpoint detection and response (EDR) solutions capable of flagging anomalous outbound HTTPS connections to unapproved domains
  • Implement network monitoring for large, encrypted payloads sent over HTTP/HTTPS to external IPs not in whitelists
  • Block known CORALDECK binaries and associated file hashes via antivirus/EDS
  • Enforce least privilege on user accounts to limit data access scope
  • Patch and harden Windows OS components to reduce vulnerable exploitation vectors
  • Regularly review user activity logs for unusual file compression or transfer scripts

Suggested Tags

APT37
exfiltration
data-theft
encrypted-transmission
Windows malware
web-protocol exfiltration
C2 domain rotation
stealthy data transfer

Confidence Assessment

The available information is derived from a single FireEye report, providing limited insight into the tool’s full capabilities. While the attribution to APT37 and its role as an exfiltration utility are confirmed, specifics such as exact encryption methods, domain rotation mechanisms, and integration with other threat actor components remain uncertain. Confidence in basic capabilities is moderate; deeper technical details require further analysis.

Description

CORALDECK is an exfiltration tool used by APT37. (Citation: FireEye APT37 Feb 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.