RogueRobin is a Windows remote access trojan used by DarkHydrus, also tracked as Lazy Meerkat, for cyberespionage against government agencies and educational institutions in the Middle East. Its delivery has involved malicious Microsoft Office documents distributed through Google Drive, including Arabic-language Excel documents containing VBA macros. Observed infection chains use command-shell and PowerShell execution, abuse the Windows Regsvr32 utility to execute scriptlets, and decode and decompress embedded Base64 payloads. A compiled C# variant was observed in 2019.
RogueRobin collects hostnames, IP addresses, domain information, usernames, and the current user's administrative status. It communicates with command-and-control infrastructure and exfiltrates system information through DNS tunneling, using Base64 to encode transmitted strings. An optional mode, disabled by default and remotely enabled through the DNS channel, uses the Google Drive API as an alternative command-and-control channel to retrieve jobs.
RogueRobin establishes persistence through Windows Startup folder shortcuts that launch PowerShell scripts at user logon. Its anti-analysis behavior includes BIOS, CPU-core, and physical-memory checks; process enumeration to detect Wireshark and Sysinternals tools; script obfuscation; and debugger detection. The 2019 variant performs debugger checks during DNS requests.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers from Palo Alto say the RogueRobin Trojan deployed in these attacks appears to be a compiled variant which will collect and send stolen system information, including hostnames, to a command-and-control (C2) server through a DNS tunnel.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Several entries describe identifying whether the current user has admin privileges, determining privilege level, identifying groups the user belongs to, or verifying execution as SYSTEM.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that collects the victim username and whether the user has admin privileges.
Malware that uses PowerShell scripts launched from Excel and for persistence via OneDrive.ps1.
Gathers victim IP address and domain information.
Backdoor malware that Base64-decodes and decompresses an embedded executable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.