RokRAT is a Windows remote access trojan and backdoor family closely associated with the North Korea-linked threat group APT37, also tracked as ScarCruft. It is used primarily for espionage and information collection and has appeared across multiple targeted intrusion campaigns against South Korean and Korea-focused victims, including researchers, policy personnel, academics, activists, media figures, and other public-interest targets.
RokRAT commonly operates through multi-stage, memory-resident infection chains delivered via spearphishing and related social-engineering lures. Observed delivery methods include malicious shortcut files, document-themed executables disguised as PDFs, ISO images, weaponized HWP documents, and trojanized software installers. Several campaigns used decoy documents tied to real events or topical themes to reduce suspicion while hidden loaders decrypted shellcode and injected the final payload into legitimate Windows processes such as explorer.exe or dism.exe. RokRAT has also been deployed through DLL sideloading and steganography-based staging.
Once active, RokRAT fingerprints the host using operating system, user, computer, process, and SMBIOS-derived hardware information to build victim identifiers and profile infected systems. Its command set supports system reconnaissance, process and drive enumeration, screenshot capture, arbitrary command execution, recursive file collection, and execution of additional payloads from memory or disk. Document theft has repeatedly focused on common office and Korean-language formats, reflecting its espionage role. Some variants also include cleanup functions to remove artifacts and traces after tasking.
A defining characteristic of RokRAT is its abuse of legitimate cloud services for command-and-control and exfiltration. Observed variants have used Dropbox, pCloud, Yandex Cloud or Yandex Disk, and Zoho WorkDrive rather than conventional dedicated C2 servers. This cloud-centric design helps blend malicious traffic with normal enterprise use and complicates blocking and detection. Variants have also used spoofed crawler-like HTTP user agents and encrypted or obfuscated communications and payloads.
RokRAT samples and campaigns have shown repeated use of process injection, in-memory decryption, API hashing, anti-analysis checks, and other defense-evasion measures. Reported anti-analysis behavior includes virtualization and debugger checks, fileless execution patterns, and selective use of legitimate processes and trusted services to conceal activity. Across campaigns, RokRAT has remained one of APT37’s signature malware families, though later activity indicates the group has also experimented with other RAT families alongside or instead of RokRAT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Once the vulnerability was exploited, a multi-stage malware chain was deployed, culminating in the execution of a variant of RokRAT, a known malicious tool used by TA-RedAnt. | The group leveraged a previously unknown vulnerability (CVE-2024-38178) in IE’s legacy Chakra engine (jscript9.dll). Delivered via seemingly innocuous toast ads—pop-up windows displayed in free software—the attack exploited the vulnerability to execute remote commands.
Vulnerability Exploited CVE-2022-41128 (Internet Explorer Vulnerability) Malware and Tools RokRAT
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The injected payload is an x64 RokRAT variant. First, it fingerprints the host and builds a victim ID from system and BIOS data. Next, it prepares cloud channels for C2. This RokRAT malware talks to pCloud, Dropbox, and Yandex Cloud rather than a plain server.
The final payload is RokRat, a remote access Trojan (RAT) primarily used by the APT37 threat group.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
RokRAT can take screenshots, collect files, enumerate drives, gather process information, and run commands issued by its operators.
It can capture the screen, list drives, and run shell commands.
The downloaded ISO file uses a filename similar to that of the seminar material booklet, making it appear to be a normal document. In addition, the ISO contains a file that appears to be a PDF document, inducing the user to execute the file while believing that they are opening the material booklet.
Analysis of the file structure found that the executable contains an embedded data area based on the "EMBED_PAYLOAD_v2" string, and this area stores information for multiple payloads.
Inside sat a file that looked like a PDF booklet. Its real extension, however, was PIF, a legacy Windows executable type. Because Windows hides known extensions by default, the file passed as a document.
Next, it injects the final payload into explorer.exe, a trusted Windows process. As a result, no new process appears, and behavior-based tools see less.
It can also remove selected traces, including files created in temporary locations and the Startup folder, after receiving an instruction to clean up.
This performs a cleanup function by deleting malicious files and related traces used in the attack, including ".VBS", ".CMD", ".BAT", and ".LNK" files created in "%APPDATA%" and the Startup folder, thereby removing autorun traces.
This RokRAT malware talks to pCloud, Dropbox, and Yandex Cloud rather than a plain server.
After initializing the cloud objects, the malware generates HTTP requests according to the REST API format of each service.
174 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
144 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan/backdoor used in a spear-phishing campaign that executes largely in memory, injects into explorer.exe, fingerprints infected hosts, uses cloud services for command-and-control, captures screens, steals files, and executes shell commands.
RokRAT is delivered via spear-phishing using a cloud-hosted ISO image and a document-like executable. The loader extracts embedded content, restores shellcode in memory, injects the RokRAT payload into explorer.exe, then gathers system details and communicates through cloud services including Dropbox, pCloud, and Yandex. It can take screenshots, collect files, enumerate drives, gather process information, execute commands, and remove selected traces.
RokRAT is the malware family explicitly referenced as the subject of an attack chain analysis. The post indicates it is used in an operation dubbed 'Capsule Vault' and is associated with ATT&CK techniques including phishing attachment abuse (T1566.002) and process injection (T1055).
RokRAT is the malware explicitly discussed in the referenced post, described as part of an analyzed attack chain in Operation Capsule Vault.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.