Last seven days
- First activity
- Jul 29, 2026
- Last activity
- Jul 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 5 IP / 0 hostnames
RokRAT is a Windows remote access trojan and backdoor family closely associated with the North Korea-linked threat group APT37, also tracked as ScarCruft.
Profile source: Mallory opens in a new tabROKRAT
RokRAT is a Windows remote access trojan and backdoor family closely associated with the North Korea-linked threat group APT37, also tracked as ScarCruft. It is used primarily for espionage and information collection and has appeared across multiple targeted intrusion campaigns against South Korean and Korea-focused victims, including researchers, policy personnel, academics, activists, media figures, and other public-interest targets.
RokRAT commonly operates through multi-stage, memory-resident infection chains delivered via spearphishing and related social-engineering lures. Observed delivery methods include malicious shortcut files, document-themed executables disguised as PDFs, ISO images, weaponized HWP documents, and trojanized software installers. Several campaigns used decoy documents tied to real events or topical themes to reduce suspicion while hidden loaders decrypted shellcode and injected the final payload into legitimate Windows processes such as explorer.exe or dism.exe. RokRAT has also been deployed through DLL sideloading and steganography-based staging.
Once active, RokRAT fingerprints the host using operating system, user, computer, process, and SMBIOS-derived hardware information to build victim identifiers and profile infected systems. Its command set supports system reconnaissance, process and drive enumeration, screenshot capture, arbitrary command execution, recursive file collection, and execution of additional payloads from memory or disk. Document theft has repeatedly focused on common office and Korean-language formats, reflecting its espionage role. Some variants also include cleanup functions to remove artifacts and traces after tasking.
A defining characteristic of RokRAT is its abuse of legitimate cloud services for command-and-control and exfiltration. Observed variants have used Dropbox, pCloud, Yandex Cloud or Yandex Disk, and Zoho WorkDrive rather than conventional dedicated C2 servers. This cloud-centric design helps blend malicious traffic with normal enterprise use and complicates blocking and detection. Variants have also used spoofed crawler-like HTTP user agents and encrypted or obfuscated communications and payloads.
RokRAT samples and campaigns have shown repeated use of process injection, in-memory decryption, API hashing, anti-analysis checks, and other defense-evasion measures. Reported anti-analysis behavior includes virtualization and debugger checks, fileless execution patterns, and selective use of legitimate processes and trusted services to conceal activity. Across campaigns, RokRAT has remained one of APT37’s signature malware families, though later activity indicates the group has also experimented with other RAT families alongside or instead of RokRAT.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e Reported operators
The injected payload is an x64 RokRAT variant. First, it fingerprints the host and builds a victim ID from system and BIOS data. Next, it prepares cloud channels for C2. This RokRAT malware talks to pCloud, Dropbox, and Yandex Cloud rather than a plain server.
The final payload is RokRat, a remote access Trojan (RAT) primarily used by the APT37 threat group.
Exploited software
MITRE ATT&CK
Reporting
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.