Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them. It also modifies filenames and creates a text file/ransom note (HowToRestoreYourFiles.txt). Rook renames files by appending the .Rook extension. For example, it renames 1.jpg to 1.jpg.Rook, 2.jpg to 2.jpg.Rook. Known victims: 9 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Rook is a ransomware威胁 actor that emerged in late 2021, known for its Babuk variant. It targets victims by encrypting their files and demanding decryption ransoms. Its activities pose significant risks to organizations due to data loss and operational disruption.

Goals & Targeting

Rook's objectives focus on generating financial profits through ransom payments. They typically target organizations with limited cybersecurity measures, such as healthcare or educational institutions. Their victims are usually those who cannot easily replace encrypted data and thus are more likely to pay the demanded ransoms.

Enhanced Description

Rook ransomware operates through a file encryption mechanism, appending .Rook extensions to victim files. This attack disrupts business operations and demands payment for decryption keys. The threat group's primary goal is financial gain, leveraging the inability of victims to access their critical data. Prevalent in 2021-2022, Rook has been observed targeting various sectors with its ransomware campaigns.

Key Capabilities

  • File encryption using .Rook extension
  • Deployment of ransom notes (HowToRestoreYourFiles.txt)
  • Targeting vulnerabilities in network security

MITRE ATT&CK Tactics

Encryption
Data Removal/Exfiltration

ATT&CK Techniques

T1059.003
T1204

Software / Tooling

Cobalt Strike (phishing)
Phishing emails with malicious attachments

Campaigns & Victims

Rook campaigns often involve large-scale phishing attempts. Their operational tempo suggests a focus on quick infections to maximize impact before detection. Known attacks have led to significant financial losses and data breaches for victims, highlighting their aggressive tactics.

IOC Patterns

  • Spear-phishing emails with attachment macros
  • Encrypted files with .Rook extension
  • Presence of HowToRestoreYourFiles.txt

Recommended Actions

  • Enhance email filtering to detect phishing attempts
  • Regularly back up data offsite
  • Implement endpoint detection tools

Suggested Tags

ransomware
financial-motivation

Confidence Assessment

Moderate confidence in the analysis. Limited details on specific targeting sectors and countries.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

15

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
financial-motivation

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 7, 2021
Last Seen
Jan 8, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.