ROKRAT is an espionage-oriented remote access trojan for Windows associated with the North Korea-linked APT37 threat group, also known as ScarCruft and Group123. It has been deployed against South Korean organizations and individuals, including human-rights organizations, defectors, journalists, academics, and specialists working on North Korean affairs, unification, defense, and diplomacy.
ROKRAT is distributed through spear-phishing emails carrying malicious Hangul Office or Microsoft Word documents, or links to archives containing malicious Windows shortcuts. Infection chains have used document vulnerability exploitation, embedded OLE objects, Visual Basic, and staged PowerShell execution. Shortcut-based campaigns display legitimate-looking decoy documents while decrypting and executing the payload in memory. ROKRAT also supports shellcode injection into legitimate Windows processes.
Its capabilities include remote command execution, downloading and executing additional payloads, process termination, file deletion, and extensive information collection. It gathers system and user information, enumerates processes, files, directories, and removable drives, collects documents and recordings, captures screenshots and audio, records keystrokes and foreground-window context, and extracts clipboard contents. Credential-stealing functionality targets browser password stores and Windows Vault.
ROKRAT uses HTTP and HTTPS and abuses legitimate web and cloud services, including Twitter, Yandex, MediaFire, pCloud, Dropbox, and Box, for command and control and exfiltration. Variants encrypt collected data before transmission over their command-and-control channels. Defense-evasion features include debugger, sandbox, and virtualization checks, obfuscated or encrypted payloads, hostname-dependent execution and string decryption, memory-resident execution, and removal of infection artifacts. Historical deployments have also included an on-demand destructive module that overwrites the master boot record and reboots the system.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The email's attachments are two different HWP documents, both leveraging same vulnerability (CVE-2013-0808). This vulnerability targets the EPS (Encapsulated PostScript) format. The purpose of the shellcode is to download a payload from the Internet.
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
These malicious documents exploited an Internet Explorer 0-day vulnerability in the JScript engine, CVE-2022-41128. The vulnerability resides within “jscript9.dll”, the JavaScript engine of Internet Explorer, and can be exploited to execute arbitrary code when rendering an attacker-controlled website.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT37 injects its malware variant, ROKRAT, into the cmd.exe process.
The purpose of the malicious documents was to install and to execute ROKRAT, a remote administration tool (RAT).
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
30 distinct techniques documented for this family, organized by ATT&CK tactic.
314 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
179 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan/backdoor used in a spear-phishing campaign that executes largely in memory, injects into explorer.exe, fingerprints infected hosts, uses cloud services for command-and-control, captures screens, steals files, and executes shell commands.
RokRAT is delivered via spear-phishing using a cloud-hosted ISO image and a document-like executable. The loader extracts embedded content, restores shellcode in memory, injects the RokRAT payload into explorer.exe, then gathers system details and communicates through cloud services including Dropbox, pCloud, and Yandex. It can take screenshots, collect files, enumerate drives, gather process information, execute commands, and remove selected traces.
RokRAT is the malware family explicitly referenced as the subject of an attack chain analysis. The post indicates it is used in an operation dubbed 'Capsule Vault' and is associated with ATT&CK techniques including phishing attachment abuse (T1566.002) and process injection (T1055).
RokRAT is the malware explicitly discussed in the referenced post, described as part of an analyzed attack chain in Operation Capsule Vault.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.