Last seven days
- First activity
- Sep 11, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2
- Host form
- 4 IP / 0 hostnames
RokRAT is a Windows espionage backdoor associated primarily with the North Korean threat actor APT37, also known as ScarCruft or RedEyes.
Profile source: Mallory opens in a new tabROKRAT
RokRAT is a Windows espionage backdoor associated primarily with the North Korean threat actor APT37, also known as ScarCruft or RedEyes. It has been used in targeted operations focused heavily on South Korean victims, including individuals and organizations connected to North Korea-related policy, human rights, unification, journalism, civil society, government, military, and education themes.
RokRAT is typically delivered through spearphishing attachments and document-based lures, especially malicious Hangul Office and Microsoft Word files that require user execution. Public reporting also documents delivery through oversized or disguised LNK shortcut files that embed decoy documents and staged script components, as well as campaigns using shellcode loaders and reflective in-memory execution. Some observed chains use Visual Basic or PowerShell-based stages, OLE-embedded scripts, BAT files, and process injection to launch the payload without leaving a conventional on-disk implant.
The malware provides a broad surveillance and collection feature set. Confirmed capabilities include browser credential theft through direct access to browser SQLite stores, credential theft via Windows Vault, keylogging, screenshot capture, audio capture, clipboard theft, process discovery, username and host profiling, file and directory enumeration, collection of local files, retrieval of additional payloads, command execution, and exfiltration of stolen data over its command-and-control channel. RokRAT has also been observed sending collected files back through the same communications path and deleting files on request for cleanup or indicator removal.
RokRAT uses HTTP and HTTPS for command and control and is notable for abusing legitimate web and cloud services for bidirectional communications and exfiltration. Reported services include major cloud storage and web platforms such as Dropbox, Yandex, MediaFire, Twitter, Box, and pCloud. This design helps blend malicious traffic with normal user activity and complicates network-based detection.
The malware incorporates multiple anti-analysis and defense-evasion measures. Documented behaviors include debugger checks, sandbox and VMware-related environment checks, victim-specific execution constraints tied to the hostname, string decryption keyed to the victim hostname, and in-memory shellcode execution. Some variants inject shellcode into benign Windows processes using native APIs. RokRAT has also been observed modifying Office-related settings to weaken protections around Visual Basic automation.
RokRAT is best characterized as a long-running, multifunction espionage implant used in targeted intrusion campaigns rather than commodity malware. Its recurring use of politically themed lures, cloud-based command infrastructure, and surveillance-oriented collection functions makes it a prominent component of APT37 operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e c2e9fbca414575d5c080d97f378024a4d131d6e1262112aebaa96eafa3592381 Reported operators
ROKRAT Windows malware ROKRAT, is a malware that is long attributed to a threat actor identified as APT37... Upon completion, malicious shellcode containing ROKRAT will be executed in memory.
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT
In this article, we describe a cluster of observed activity that deploys ROKRAT... we have observed a shift to delivering ROKRAT with LNK files disguised as legitimate documents.
Exploited software
MITRE ATT&CK
Reporting
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations. Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.
Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.
Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.