Skip to content

RokRAT

Also known as: DOGCALL

It is a backdoor commonly distributed as an encoded

binary file downloaded and decrypted by shellcode following the

exploitation of weaponized documents. DOGCALL is capable of

capturing screenshots, logging keystrokes, evading analysis with

anti-virtual machine detections, and leveraging cloud storage APIs

such as Cloud, Box, Dropbox, and Yandex.

Linked Threat Actors

APT37

C2 Infrastructure

Hosting/VPS 80%
ISP/Residential 20%

Last 7 days

Jun 12, 2026
C2 Hosts: 4
Jun 11, 2026
C2 Hosts: 1

Further Reading