Skip to content

ROKRAT

RokRAT is a Windows remote access trojan and backdoor family closely associated with the North Korea-linked threat group APT37, also tracked as ScarCruft.

Profile source: Mallory opens in a new tab

ROKRAT

Family profile

RokRAT is a Windows remote access trojan and backdoor family closely associated with the North Korea-linked threat group APT37, also tracked as ScarCruft. It is used primarily for espionage and information collection and has appeared across multiple targeted intrusion campaigns against South Korean and Korea-focused victims, including researchers, policy personnel, academics, activists, media figures, and other public-interest targets.

RokRAT commonly operates through multi-stage, memory-resident infection chains delivered via spearphishing and related social-engineering lures. Observed delivery methods include malicious shortcut files, document-themed executables disguised as PDFs, ISO images, weaponized HWP documents, and trojanized software installers. Several campaigns used decoy documents tied to real events or topical themes to reduce suspicion while hidden loaders decrypted shellcode and injected the final payload into legitimate Windows processes such as explorer.exe or dism.exe. RokRAT has also been deployed through DLL sideloading and steganography-based staging.

Once active, RokRAT fingerprints the host using operating system, user, computer, process, and SMBIOS-derived hardware information to build victim identifiers and profile infected systems. Its command set supports system reconnaissance, process and drive enumeration, screenshot capture, arbitrary command execution, recursive file collection, and execution of additional payloads from memory or disk. Document theft has repeatedly focused on common office and Korean-language formats, reflecting its espionage role. Some variants also include cleanup functions to remove artifacts and traces after tasking.

A defining characteristic of RokRAT is its abuse of legitimate cloud services for command-and-control and exfiltration. Observed variants have used Dropbox, pCloud, Yandex Cloud or Yandex Disk, and Zoho WorkDrive rather than conventional dedicated C2 servers. This cloud-centric design helps blend malicious traffic with normal enterprise use and complicates blocking and detection. Variants have also used spoofed crawler-like HTTP user agents and encrypted or obfuscated communications and payloads.

RokRAT samples and campaigns have shown repeated use of process injection, in-memory decryption, API hashing, anti-analysis checks, and other defense-evasion measures. Reported anti-analysis behavior includes virtualization and debugger checks, fileless execution patterns, and selective use of legitimate processes and trusted services to conceal activity. Across campaigns, RokRAT has remained one of APT37’s signature malware families, though later activity indicates the group has also experimented with other RAT families alongside or instead of RokRAT.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Post Exploitation
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 29, 2026
Last activity
Jul 29, 2026
Feed role
C2 / Distribution
Host form
5 IP / 0 hostnames

Leading locations

  • HK2
  • US2
  • CH1

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • DEDIK SERVICES LIMITED1
  • Hong Kong Communications International Co., Limited1
  • XNNET LLC1

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
APT37

The injected payload is an x64 RokRAT variant. First, it fingerprints the host and builds a victim ID from system and BIOS data. Next, it prepares cloud channels for C2. This RokRAT malware talks to pCloud, Dropbox, and Yandex Cloud rather than a plain server.

RedEyes

The final payload is RokRat, a remote access Trojan (RAT) primarily used by the APT37 threat group.

Exploited software

Vulnerabilities linked to ROKRAT

2 CVEs

MITRE ATT&CK

ROKRAT in ATT&CK

85 distinct techniques

Techniques

85 techniques
T1102 Web Service T1620 Reflective Code Loading T1567 Exfiltration Over Web Service T1059.003 Windows Command Shell T1082 System Information Discovery T1071 Application Layer Protocol T1113 Screen Capture T1083 File and Directory Discovery T1140 Deobfuscate/Decode Files or Information T1566.002 Spearphishing Link T1055 Process Injection T1005 Data from Local System T1036 Masquerading T1560 Archive Collected Data T1070 Indicator Removal T1057 Process Discovery T1059 Command and Scripting Interpreter T1105 Ingress Tool Transfer T1204.002 Malicious File T1583.007 Serverless T1566.001 Spearphishing Attachment T1070.004 File Deletion T1071.001 Web Protocols T1027.009 Embedded Payloads T1033 System Owner/User Discovery T1027.007 Dynamic API Resolution T1204 User Execution T1102.002 Bidirectional Communication T1036.006 Space after Filename T1562 Impair Defenses T1497.001 System Checks T1112 Modify Registry T1012 Query Registry T1027.011 Fileless Storage T1656 Impersonation T1574 Hijack Execution Flow T1574.013 KernelCallbackTable T1027.003 Steganography T1218 System Binary Proxy Execution T1567.002 Exfiltration to Cloud Storage T1055.001 Dynamic-link Library Injection T1566.003 Spearphishing via Service T1134.004 Parent PID Spoofing T1027 Obfuscated Files or Information T1204.001 Malicious Link T1543 Create or Modify System Process T1497 Virtualization/Sandbox Evasion T1562.001 Disable or Modify Tools T1059.001 PowerShell T1547.009 Shortcut Modification T1106 Native API T1566 Phishing T1564.003 Hidden Window T1622 Debugger Evasion T1041 Exfiltration Over C2 Channel T1078.001 Default Accounts T1059.005 Visual Basic T1055.012 Process Hollowing T1555 Credentials from Password Stores T1016.001 Internet Connection Discovery T1518 Software Discovery T1115 Clipboard Data T1486 Data Encrypted for Impact T1114 Email Collection T1539 Steal Web Session Cookie T1120 Peripheral Device Discovery T1129 Shared Modules T1189 Drive-by Compromise T1203 Exploitation for Client Execution T1555.003 Credentials from Web Browsers T1195 Supply Chain Compromise T1195.002 Compromise Software Supply Chain T1055.003 Thread Execution Hijacking T1608.001 Upload Malware T1584.004 Server T1574.001 DLL T1589 Gather Victim Identity Information T1593.001 Social Media T1587 Develop Capabilities T1027.005 Indicator Removal from Tools T1010 Application Window Discovery T1056.001 Keylogging T1480.001 Environmental Keying T1555.004 Windows Credential Manager T1123 Audio Capture

Reporting

Research mentioning ROKRAT

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Sep 12
Mitre Attack Website

Boot or Logon Autostart Execution, Technique T1547 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.