Skip to content

ROKRAT

RokRAT is a Windows espionage backdoor associated primarily with the North Korean threat actor APT37, also known as ScarCruft or RedEyes.

Profile source: Mallory opens in a new tab

ROKRAT

Family profile

RokRAT is a Windows espionage backdoor associated primarily with the North Korean threat actor APT37, also known as ScarCruft or RedEyes. It has been used in targeted operations focused heavily on South Korean victims, including individuals and organizations connected to North Korea-related policy, human rights, unification, journalism, civil society, government, military, and education themes.

RokRAT is typically delivered through spearphishing attachments and document-based lures, especially malicious Hangul Office and Microsoft Word files that require user execution. Public reporting also documents delivery through oversized or disguised LNK shortcut files that embed decoy documents and staged script components, as well as campaigns using shellcode loaders and reflective in-memory execution. Some observed chains use Visual Basic or PowerShell-based stages, OLE-embedded scripts, BAT files, and process injection to launch the payload without leaving a conventional on-disk implant.

The malware provides a broad surveillance and collection feature set. Confirmed capabilities include browser credential theft through direct access to browser SQLite stores, credential theft via Windows Vault, keylogging, screenshot capture, audio capture, clipboard theft, process discovery, username and host profiling, file and directory enumeration, collection of local files, retrieval of additional payloads, command execution, and exfiltration of stolen data over its command-and-control channel. RokRAT has also been observed sending collected files back through the same communications path and deleting files on request for cleanup or indicator removal.

RokRAT uses HTTP and HTTPS for command and control and is notable for abusing legitimate web and cloud services for bidirectional communications and exfiltration. Reported services include major cloud storage and web platforms such as Dropbox, Yandex, MediaFire, Twitter, Box, and pCloud. This design helps blend malicious traffic with normal user activity and complicates network-based detection.

The malware incorporates multiple anti-analysis and defense-evasion measures. Documented behaviors include debugger checks, sandbox and VMware-related environment checks, victim-specific execution constraints tied to the hostname, string decryption keyed to the victim hostname, and in-memory shellcode execution. Some variants inject shellcode into benign Windows processes using native APIs. RokRAT has also been observed modifying Office-related settings to weaken protections around Visual Basic automation.

RokRAT is best characterized as a long-running, multifunction espionage implant used in targeted intrusion campaigns rather than commodity malware. Its recurring use of politically themed lures, cloud-based command infrastructure, and surveillance-oriented collection functions makes it a prominent component of APT37 operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 11, 2026
Last activity
Sep 11, 2026
Feed role
C2
Host form
4 IP / 0 hostnames

Leading locations

  • HK2
  • US2

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • Hong Kong Communications International Co., Limited1
  • XNNET LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
APT37

ROKRAT Windows malware ROKRAT, is a malware that is long attributed to a threat actor identified as APT37... Upon completion, malicious shellcode containing ROKRAT will be executed in memory.

RedEyes

AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT

APT-C-28

AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT

ITG10

AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT

Moldy Pisces

AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178) ... LNK File Disguised as Certificate Distributing RokRAT Malware ... Reverse Engineering RokRAT: A Closer Look at APT37’s Onedrive-Based Attack Vector ... Introducing ROKRAT

Inky Squid

In this article, we describe a cluster of observed activity that deploys ROKRAT... we have observed a shift to delivering ROKRAT with LNK files disguised as legitimate documents.

Exploited software

Vulnerabilities linked to ROKRAT

3 CVEs

MITRE ATT&CK

ROKRAT in ATT&CK

92 distinct techniques

Techniques

92 techniques
T1071 Application Layer Protocol T1057 Process Discovery T1059.001 PowerShell T1564 Hide Artifacts T1204.001 Malicious Link T1105 Ingress Tool Transfer T1566.001 Spearphishing Attachment T1059.003 Windows Command Shell T1106 Native API T1047 Windows Management Instrumentation T1489 Service Stop T1070.004 File Deletion T1204.002 Malicious File T1620 Reflective Code Loading T1129 Shared Modules T1012 Query Registry T1005 Data from Local System T1123 Audio Capture T1027 Obfuscated Files or Information T1082 System Information Discovery T1555.003 Credentials from Web Browsers T1112 Modify Registry T1102.002 Bidirectional Communication T1622 Debugger Evasion T1140 Deobfuscate/Decode Files or Information T1115 Clipboard Data T1083 File and Directory Discovery T1555.004 Windows Credential Manager T1567.002 Exfiltration to Cloud Storage T1056.001 Keylogging T1055 Process Injection T1071.001 Web Protocols T1113 Screen Capture T1033 System Owner/User Discovery T1497.001 System Checks T1059.005 Visual Basic T1041 Exfiltration Over C2 Channel T1480.001 Environmental Keying T1010 Application Window Discovery T1204 User Execution T1102 Web Service T1555 Credentials from Password Stores T1055.012 Process Hollowing T1560 Archive Collected Data T1027.009 Embedded Payloads T1059 Command and Scripting Interpreter T1497 Virtualization/Sandbox Evasion T1567 Exfiltration Over Web Service T1036 Masquerading T1218.005 Mshta T1027.011 Fileless Storage T1547.001 Registry Run Keys / Startup Folder T1543 Create or Modify System Process T1119 Automated Collection T1007 System Service Discovery T1070 Indicator Removal T1203 Exploitation for Client Execution T1566 Phishing T1566.002 Spearphishing Link T1583.007 Serverless T1027.007 Dynamic API Resolution T1036.006 Space after Filename T1562 Impair Defenses T1656 Impersonation T1574 Hijack Execution Flow T1574.013 KernelCallbackTable T1027.003 Steganography T1218 System Binary Proxy Execution T1055.001 Dynamic-link Library Injection T1566.003 Spearphishing via Service T1134.004 Parent PID Spoofing T1562.001 Disable or Modify Tools T1547.009 Shortcut Modification T1564.003 Hidden Window T1078.001 Default Accounts T1016.001 Internet Connection Discovery T1518 Software Discovery T1486 Data Encrypted for Impact T1114 Email Collection T1539 Steal Web Session Cookie T1120 Peripheral Device Discovery T1189 Drive-by Compromise T1195 Supply Chain Compromise T1195.002 Compromise Software Supply Chain T1055.003 Thread Execution Hijacking T1608.001 Upload Malware T1584.004 Server T1574.001 DLL T1589 Gather Victim Identity Information T1593.001 Social Media T1587 Develop Capabilities T1027.005 Indicator Removal from Tools

Reporting

Research mentioning ROKRAT

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jun 23
Darkatlas

Bluenoroff (APT38) Live Infrastructure Hunting - Darkatlas

North Korea-linked Lazarus Group and its financially motivated subgroup Bluenoroff/APT38 have been tied to long-running intrusions against banks, SWIFT-connected environments, cryptocurrency businesses, casinos, and other financial targets worldwide. Reporting from multiple investigations links the actors to operations including the Bangladesh Bank theft, compromises at Bancomext and Banco de Chile, and intrusions at banks in Southeast Asia and Europe. Investigators found that the group maintained access for months, compromised SWIFT Alliance infrastructure, patched SWIFT-related components to suppress integrity checks, harvested transaction data, and used keylogging, lateral movement, and anti-forensic measures to conceal activity and disrupt investigations. Researchers also documented recurring Lazarus tradecraft across these campaigns, including spear phishing, watering-hole attacks, brute force, exploitation of web and client vulnerabilities, fake-TLS command-and-control, service-based persistence, and reuse of malware families and tooling. Technical reporting connected incidents through shared backdoor design, tunneling tools, SWIFT-focused modules, and malware such as SQCSVC and SWPSVC, while newer infrastructure hunting identified phishing domains, linked IP space, and a macOS sample named localfile~.x64 communicating with 104.168.136.24. The combined findings reinforce attribution of these financially driven operations to the Lazarus ecosystem and show an adaptive capability spanning traditional banking networks and digital-asset platforms.

Sep 12
Mitre Attack Website

Boot or Logon Autostart Execution, Technique T1547 - Enterprise | MITRE ATT&CK®

May 25
Cyble Blog Historic

Invicta Stealer Spreads Via Fake GoDaddy Refund Invoices

Invicta Stealer is being spread through phishing emails that impersonate GoDaddy refund invoices, using an infection chain that begins with a malicious HTML attachment and progresses through ZIP, LNK, HTA, and PowerShell stages before installing the information-stealing malware. Researchers said the malware’s developer has promoted the family on Telegram, YouTube, and GitHub, including a free builder that appears to have lowered the barrier to entry for other threat actors and increased the stealer’s circulation. Once executed by the victim, Invicta Stealer gathers extensive host and user data, including browser information, Discord data, cryptocurrency wallet contents, Steam and KeePass artifacts, installed application details, and files from Desktop and Documents, then compresses and exfiltrates the data to a Discord webhook or other command-and-control endpoint. The campaign aligns with common user execution tradecraft in phishing-led intrusions, and the malware also uses anti-analysis features such as encrypted strings, syscalls, and multithreading while collecting system and application context from infected machines.

Mar 1
Elastic Security Labs

Detect Credential Access with Elastic Security | Elastic Security Labs

Elastic Endpoint Security added kernel-driver-derived file and registry telemetry to detect access to sensitive credential stores, including browser data, Windows SAM and LSA secrets, cached domain credentials, credential files, and Windows Credential Manager. Its behavior protections can block high-confidence credential-theft activity associated with tools and malware such as Mimikatz, LaZagne, AgentTesla, FormBook, and Poulight Stealer; KQL and EQL hunting can also identify processes opening multiple sensitive stores or SMB access following a network logon. Attackers commonly extract saved browser usernames, passwords, cookies, and session tokens from stores such as Chrome’s Login Data and Firefox’s key3.db, key4.db, and logins.json. They also dump Windows LSA secrets and cached domain credentials using utilities including Mimikatz, reg save, Impacket secretsdump.py, CrackMapExec, and gsecdump. Cached Windows credentials are generally stored as DCC2/MS-Cache v2 hashes and require offline cracking rather than pass-the-hash, while Linux Active Directory integrations may retain cached credentials in SSSD or Quest database files.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.