Rook is a 64-bit Windows ransomware family first publicly observed in late 2021. It encrypts local drives, mounted volumes, accessible network resources, and operator-supplied paths using per-file AES keys protected through a victim-specific RSA key pair; its encryption implementation uses Mbed TLS. Encrypted files are marked with a Rook-specific extension and ransom notes are written into affected directories. Rook supports a dual-extortion model in which operators claim to exfiltrate data and threaten public disclosure through a leak site if ransom demands are not met.
Rook impairs recovery and maximizes encryption impact by stopping selected backup, database, security, and productivity processes and services, deleting volume shadow copies, and terminating processes that lock target files. It uses multithreaded directory traversal and encryption, excludes critical operating-system and application locations to preserve system usability, and deletes itself after execution. Some variants use a legitimate Process Hacker driver to assist process termination. Rook samples have commonly been packed with UPX, while others use virtualization-based protection.
Rook has substantial code-level overlap with the leaked Babuk ransomware source code, including service and process termination, shadow-copy removal, drive enumeration, and encryption workflow components. It is also closely related to Pandora and NightSky ransomware, with the latter assessed as likely a Rook fork. Reported delivery includes phishing and deployment through post-compromise frameworks such as Cobalt Strike. In 2025–2026, the North Korea-aligned Andariel group was reported attempting to deploy Rook within a South Korean engineering organization involved in liquid-hydrogen and nuclear-industry equipment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We also uncovered the reemergence of Andariel in South Korea, where the group deployed TigerRAT and attempted to spread Rook ransomware within an engineering company
"ESET APT Activity Report Q4 2025–Q1 2026" published by ESET. #Andariel, #DangerousPassword, #DeceptiveDevelopment, #DreamJob, #Rook, #ScarCruft, #DPRK, #CTI
Their payloads are sometimes rebuilt from existing for-purchase ransomware tools like Rook, which shares code similarity with the Babuk ransomware family.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Individual samples are typically UPX packed, although alternate packers/crypters have been observed such as VMProtect.
After hiding itself, ROOK also calls SetFileInformationByHandle again to set the file to be deleted once all handles are closed at the end.
Babuk and Rook use EnumDependentServicesA API to retrieve the name and status of each service that depends on the specified service before terminating. They enumerate all services in the system and stop all of those which exist in a hardcoded list in the malware.
both Rook and Babuk use the functions CreateToolhelp32Snapshot , Process32FirstW , Process32NextW , OpenProcess , and TerminateProcess to enumerate running processes and kill any found to match those in a hardcoded list.
Both Babuk and Rook check if the sample is executed in a 64-bit OS, then delete the shadow volumes of the user machine.
Finally, the malware calls GetLogicalDrives to iterate through all the drives in the system and traverse them.
Rook embraces a dual-pronged extortion approach: an initial demand for payment to unlock encrypted files, followed by public threats via the operators’ website to leak exfiltrated data should the victim fail to comply with the ransom demand.
For each dependent service, the malware calls OpenServiceA to retrieve its handle and ControlService to send a control stop code to stop it. | For each process whose name is in the list of processes to be terminated, the malware calls OpenProcess to retrieve the process’s handle and TerminateProcess to terminate it.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post references: "Ransomware Landscape in H1 2026: Statistics and Key Issues" ... #Ransomware, #Medusa, #Rook, #puNK012.
Mentioned as a ransomware variant developed from leaked Babuk source code.
"ESET APT Activity Report Q4 2025–Q1 2026" published by ESET. #Andariel, #DangerousPassword, #DeceptiveDevelopment, #DreamJob, #Rook, #ScarCruft, #DPRK, #CTI
A ransomware family that Andariel attempted to spread within a South Korean engineering company.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.