Rook
- First seen
- 2022-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:02:20
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector technology-and-telecommunications education-and-nonprofits
Context
Rook is a ransomware family known for targeting various sectors such as healthcare, financial services, and government entities. It encrypts files and demands a ransom payment in cryptocurrency for decryption keys.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Rook_Auto (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- blog.cyble.com — Deep Dive Analysis Pandora Ransomware (report)
- sentinelone.com — New Rook Ransomware Feeds Off The Code Of Babuk (report)
- twitter.com — 1464317136944435209 (report)
- chuongdong.com — Rookransomware (report)
- github.com — Nightsky Ransomware%E2%80%93Just A Rook Rw Fork In Vmprotect Suit.Md (report)
- seguranca-informatica.pt — Rook Ransomware Analysis (report)
- ransomlook.io — Rook (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Rook (report)