ROKRAT
MITRE ATT&CK: S0240 View on attack.mitre.org
Aliases: DOGCALL, ROKRAT
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 67 (67 malicious)
- Last IoC activity
- 2026-09-01 19:45:07
- Profile updated
- 2026-07-07 12:52:33
Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment
Targeted regions: country_code:kr
Context
ROKRAT is a cloud-based remote access tool (RAT) used by APT37 to target victims in South Korea. APT37 has used ROKRAT during several campaigns from 2016 through 2021.
Recent IoC activity
67 malicious indicators in Maltiverse are attributed to ROKRAT (S0240). The 20 most recently updated:
Detection coverage
- 4 YARA rules
- 566 Sigma rules
Malware & tools used
- Modify Registry (attack-pattern)
- Audio Capture (attack-pattern)
- Query Registry (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Keylogging (attack-pattern)
- Native API (attack-pattern)
- Debugger Evasion (attack-pattern)
- Process Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Visual Basic (attack-pattern)
- Windows Credential Manager (attack-pattern)
- Environmental Keying (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Clipboard Data (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- System Checks (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Screen Capture (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Process Injection (attack-pattern)
- System Information Discovery (attack-pattern)
Used by threat actors
- APT37 (threat-actor)
Detection rules
- MALPEDIA_Win_Rokrat_Auto (yara-rule)
- SEKOIA_Backdoor_Win_Rokrat (yara-rule)
- SIGNATURE_BASE_APT_NK_Scarcruft_Evolved_ROKRAT (yara-rule)
- CAPE_Rokrat (yara-rule)
Reports & references
- Mandiant — Rpt Apt37 (report)
- Cisco Talos — Korea In Crosshairs (report)
- Cisco Talos — Korea In Crosshairs (report)
- Kaspersky — 90729 (report)
- Palo Alto Unit 42 — Moldypisces (report)
- pwc.com — Yir Cyber Threats Annex Download (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Kaspersky — 91897 (report)
- ibm.com — Z81Avoy7 (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- medium.com — Scarcruft Bolsters Arsenal For Targeting Individual Android Devices 97D2Bcef4Ab (report)
- kindredsec.com — An Overview Of Public Platform C2S (report)
- kindredsec.wordpress.com — An Overview Of Public Platform C2S (report)
- twitter.com — 1575103839115804672 (report)
- ptsecurity.com — Antisandbox Techniques (report)
- research.checkpoint.com — Chain Reaction Rokrats Missing Link (report)
- picussecurity.com — Picus 10 Critical Mitre Attck Techniques T1055 Process Injection (report)
- cocomelonc.github.io — Malware Tricks 47 (report)
- intezer.com — Apt37 Final1Stspy Reaping The Freemilk (report)
- cocomelonc.github.io — Malware Tricks 46 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rokrat (report)
- threatmon.io — Reverse Engineering Rokrat A Closer Look At Apt37S Onedrive Based Attack Vector (report)
- v3lo.tistory.com — 24 (report)
- blog.malwarebytes.com — Retrohunting Apt37 North Korean Apt Used Vba Self Decode Technique To Inject Rokrat (report)
- medium.com — Matryoshka Variant Of Rokrat Apt37 Scarcruft 69774Ea7Bf48 (report)