ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool DOGCALL

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: DOGCALL

NamesDOGCALL
CategoryMalware
TypeBackdoor, Keylogger, Info stealer
Description(FireEye) DOGCALL is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. DOGCALL is capable of capturing screenshots, logging keystrokes, evading analysis with anti-virtual machine detections, and leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex.

DOGCALL was used to target South Korean Government and military organizations in March and April 2017.

The malware is typically dropped using an HWP exploit in a lure document.

The wiper tool, RUHAPPY, was found on some of the systems targeted by DOGCALL. While DOGCALL is primarily an espionage tool, RUHAPPY is a destructive wiper tool meant to render systems inoperable.
Information<https://www2.fireeye.com/rs/848-DID-242/images/rpt_APT37.pdf>
MITRE ATT&CK<https://attack.mitre.org/software/S0213/>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:dogcall>

Last change to this tool card: 22 April 2020

Download this tool card in JSON format

All groups using tool DOGCALL

ChangedNameCountryObserved

APT groups

 Reaper, APT 37, Ricochet Chollima, ScarCruftNorth Korea2012-Dec 2020X

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key