Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware ROKRAT

ROKRAT

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

ROKRAT is a sophisticated cloud‑based RAT used by APT37 to gain persistent remote control over Windows systems in South Korea. It employs encrypted HTTPS C2 channels, keylogging, and credential theft capabilities to exfiltrate sensitive data and facilitate lateral movement within victim networks. The malware’s modular architecture and use of stealthy persistence mechanisms make it a high‑risk threat for targeted organizations.

Enhanced Description

ROKRAT is a cloud‑based Remote Access Trojan (RAT) developed for the APT37 threat actor, an advanced persistent threat group that has operated in South Korea since at least 2016. The malware functions as a fully featured remote shell, providing attackers remote control over infected Windows endpoints and enabling credential harvesting, data exfiltration, and lateral movement inside corporate networks. The payload leverages encrypted HTTPS traffic to connect to a command‑and‑control (C2) infrastructure hosted in the cloud, which helps it evade signature‑based defenses and blend in with legitimate web traffic. ROKRAT’s modular design includes keylogging, screenshot capture, process injection, and DLL hijacking components that facilitate persistence and stealth. APT37 has deployed ROKRAT across multiple campaigns targeting South Korean governmental agencies, military units, and private sector firms. The group’s use of the tool appears to focus on gathering privileged credentials, sensitive business data, and strategic information for intelligence collection or sabotage.

Key Capabilities

  • Remote desktop control via VNC/remote GUI
  • Encrypted HTTPS command‑and‑control communications
  • Keylogging and screenshot capture
  • Process injection and DLL hijacking
  • Credential dumping (hashes and plaintext)
  • Persistence through registry run keys or scheduled tasks
  • Lateral movement via SMB/Windows Admin Shares
  • Data exfiltration with obfuscated traffic

ATT&CK Techniques

T1071
T1105
T1059
T1055
T1083
T1112

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions that monitor for unusual outbound HTTPS connections to unknown cloud endpoints.
  • Block or quarantine the ROKRAT binary and related modules on all Windows systems.
  • Use host‑based firewalls to restrict inbound SMB/HTTP connections to approved hosts only.
  • Patch vulnerable Windows components and enforce patch management policies.

Suggested Tags

APT37
RAT
Remote Access Tool
Cloud‑based RAT
South Korea Targeting
Windows Malware
Command and Control

Confidence Assessment

The analysis is supported by multiple reputable vendor reports (Talos, Volexity) and documented campaigns dating from 2016–2021, giving medium‑to‑high confidence in the described capabilities. However, full technical details such as source IP ranges for C2 servers, encryption keys used, and complete IOCs are not disclosed in this dataset, leaving gaps in precise detection rules.

Description

ROKRAT is a cloud-based remote access tool (RAT) used by APT37 to target victims in South Korea. APT37 has used ROKRAT during several campaigns from 2016 through 2021.(Citation: Talos ROKRAT)(Citation: Talos Group123)(Citation: Volexity InkySquid RokRAT August 2021)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.