ROKRAT

MITRE ATT&CK: S0240 View on attack.mitre.org

Aliases: DOGCALL, ROKRAT

First seen
2016-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
67 (67 malicious)
Last IoC activity
2026-09-01 19:45:07
Profile updated
2026-07-07 12:52:33

Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment

Targeted regions: country_code:kr

Context

ROKRAT is a cloud-based remote access tool (RAT) used by APT37 to target victims in South Korea. APT37 has used ROKRAT during several campaigns from 2016 through 2021.

Recent IoC activity

67 malicious indicators in Maltiverse are attributed to ROKRAT (S0240). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 730e7cf897c39641a53c1e8d4ae6cec4c57a79fcab3f4fb6c031ec5a7586cf99 2026-09-01 2
file sample 6c7ccc122fac3ed22879b0b82b2874a375ec9236827127ec784eafc607740a83 2026-09-01 3
file sample 54eafd9bd8105444ccd57e92dc3bee43166532da0a71e26686fe9913956f6243 2026-08-28 2
file sample 5fda36bec5b1d5ec526e5b044a6b30b7afa1d0d5465ffa7c470efc9358ebc4b5 2026-08-25 3
file sample 38b26e2364bc081a90145838451341f14bda3cbd15bba54bf0114cab5d2f8667 2026-08-24 3
file sample 88696cf17417a2339b63f9452404c839 2026-08-22 3
file sample 249ff1abee706220f65aa47ef1c839a44b54979466ac531231858c6cf8e50e99 2026-08-18 3
file sample 1cc823962da2fa7a4d6fee8335ce8d92c6b44be627803cba85a1bdb8184da1d9 2026-08-17 3
file sample 1c19018dec9dbe68fc48099c662be25062e7a43e6658bf396c6cc8fb2f6d21af 2026-08-17 3
file sample 15ad522ec1e3313921cb6d311a87bca109ac311a3bfd416019fe64a7c60b3dc1 2026-08-17 3
file sample 2026-08-01_140108bf78ab554f9fbc874eab22c090_cobalt-strike_icedid_njrat_remcos... 2026-08-02 1
file sample 884b586231504947e47b158b414747323442185162aa32d348f21ce61c9124ce 2026-07-27 2
file sample 2026-07-26_a122fa868f22877901e0a00cfc574b49_icedid_mespinoza_njrat_ryuk 2026-07-26 1
file sample 2026-07-23_f0360e0317f47b1ddb4a4f9d40d76a49_icedid_mespinoza_njrat_ryuk 2026-07-24 1
file sample c25e5e87d1e665197209e7aaec64e484ce30e2dabcc9e457c5593ac6c7bb5686 2026-06-17 1
file sample Betaling.exe 2026-04-26 3
file sample 2bbb433718d061e161f1d0e224451746.exe 2026-04-17 2
file sample 이상용.lnk 2026-04-17 2
file sample 2025 북한인권 청년 아카데미 강의 주제.pdf.lnk 2026-04-06 2
file sample odeme tarihleri.scr 2026-04-03 3

Detection coverage

  • 4 YARA rules
  • 566 Sigma rules

Malware & tools used

  • Modify Registry (attack-pattern)
  • Audio Capture (attack-pattern)
  • Query Registry (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Keylogging (attack-pattern)
  • Native API (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Process Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Visual Basic (attack-pattern)
  • Windows Credential Manager (attack-pattern)
  • Environmental Keying (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • System Checks (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Screen Capture (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Process Injection (attack-pattern)
  • System Information Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Rokrat_Auto (yara-rule)
  • SEKOIA_Backdoor_Win_Rokrat (yara-rule)
  • SIGNATURE_BASE_APT_NK_Scarcruft_Evolved_ROKRAT (yara-rule)
  • CAPE_Rokrat (yara-rule)

Reports & references

  • Mandiant — Rpt Apt37 (report)
  • Cisco Talos — Korea In Crosshairs (report)
  • Cisco Talos — Korea In Crosshairs (report)
  • Kaspersky — 90729 (report)
  • Palo Alto Unit 42 — Moldypisces (report)
  • pwc.com — Yir Cyber Threats Annex Download (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Kaspersky — 91897 (report)
  • ibm.com — Z81Avoy7 (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • medium.com — Scarcruft Bolsters Arsenal For Targeting Individual Android Devices 97D2Bcef4Ab (report)
  • kindredsec.com — An Overview Of Public Platform C2S (report)
  • kindredsec.wordpress.com — An Overview Of Public Platform C2S (report)
  • twitter.com — 1575103839115804672 (report)
  • ptsecurity.com — Antisandbox Techniques (report)
  • research.checkpoint.com — Chain Reaction Rokrats Missing Link (report)
  • picussecurity.com — Picus 10 Critical Mitre Attck Techniques T1055 Process Injection (report)
  • cocomelonc.github.io — Malware Tricks 47 (report)
  • intezer.com — Apt37 Final1Stspy Reaping The Freemilk (report)
  • cocomelonc.github.io — Malware Tricks 46 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Rokrat (report)
  • threatmon.io — Reverse Engineering Rokrat A Closer Look At Apt37S Onedrive Based Attack Vector (report)
  • v3lo.tistory.com — 24 (report)
  • blog.malwarebytes.com — Retrohunting Apt37 North Korean Apt Used Vba Self Decode Technique To Inject Rokrat (report)
  • medium.com — Matryoshka Variant Of Rokrat Apt37 Scarcruft 69774Ea7Bf48 (report)

External references