APT37, also tracked as ScarCruft/RedEyes, has continued delivering the RokRAT backdoor through spear-phishing campaigns that use malicious .lnk shortcut files, often packaged in ZIP or ISO archives and disguised as certificates, conference invitations, or other South Korea-focused policy and security documents. Researchers reported that the LNK files launch hidden cmd and PowerShell chains to extract decoy files, stage payloads from locations such as %public%, and retrieve additional components from cloud storage including OneDrive and Dropbox. The activity has primarily targeted South Korean users, especially people involved in North Korea-related issues, unification, military, education, and activist communities, while earlier RokRAT operations also used malicious HWP documents exploiting CVE-2013-0808.
Once executed, RokRAT performs host reconnaissance, steals credentials and other user data, captures screenshots and process information, executes attacker commands, and can download further malware, while hiding command-and-control and exfiltration traffic inside trusted cloud services such as pCloud, Yandex, Dropbox, OneDrive, and previously Twitter and Mediafire. Multiple reports said the malware uses in-memory or fileless execution, anti-analysis checks, and HTTP headers masquerading as Googlebot, complicating detection by signature-based tools. Analysts linked the campaigns to APT37 through recurring malware code, infrastructure patterns, lure themes, and tradecraft, and noted that the group shifted from document-based delivery to LNK-driven infection chains after macro-blocking changes made older techniques less reliable.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
The 360 Advanced Threat Research Institute reported that APT-C-28/ScarCruft/APT37 ran a cyber espionage campaign in 2024 using ZIP archives with malicious LNK files to deliver a fileless RokRat infection chain. The report said the updated variant decrypted shellcode in memory, used stronger anti-forensics and process hollowing, and communicated with C2 while masquerading as Googlebot traffic.
ASEC reported that RedEyes/ScarCruft was distributing RokRAT-related malware in archive files uploaded to legitimate websites, including REPORT.ZIP containing a malicious LNK disguised as a South Korean public-sector document. The analysis described RunOnce persistence, PowerShell and mshta retrieval of additional scripts, attacker C2 at 75.119.136[.]207, and command support for reconnaissance, file transfer, registry changes, and compression.
In April 2023, APT37/RedEyes used malicious LNK files such as '북 외교관 선발파견 및 해외공관.lnk' and '북한외교정책결정과정.lnk' to drop decoy documents and execute a PowerShell-and-BAT infection chain ending in RokRAT. Check Point and ASEC both described OneDrive-hosted payload retrieval and in-memory execution.
ASEC stated that in the month before its April 2023 report, RedEyes distributed CHM malware disguised as a security email from a Korean financial company. This was cited as prior activity preceding the LNK-based RokRAT campaign.
In January 2023, a lure named 'projects in Libya.zip' used stolen oil-and-gas documents and a 42.5 MB LNK file masquerading as a PDF. Check Point linked this campaign to the evolving LNK-based ROKRAT delivery tradecraft.
A December 2022 malicious Word document named '사례비_지급의뢰서.doc' used macros to inject shellcode into notepad.exe and load ROKRAT in memory. The lure referenced South Korea’s Ministry of Unification.
In November 2022, a ZIP file named 'securityMail.zip' used overlapping LNK tradecraft but ultimately deployed the commodity malware Amadey instead of ROKRAT. Check Point cited this as evidence of shared infrastructure or operations around the infection chain.
A July 2022 ZIP lure named '(0722)상임위원회 및 상설특별위원회 위원 명단(최종).zip' contained an LNK that dropped a decoy HWP document about South Korea’s National Assembly committees. Check Point assessed the lure was likely weaponized within one day of the decoy document appearing on the National Assembly website.
The first LNK-based sample discussed by Check Point was discovered in July 2022, marking a shift from HWP and Word-based delivery toward oversized LNK files in multi-stage infection chains. Check Point noted this occurred in the same month Microsoft began enforcing macro blocking for untrusted Office files.
In April 2022, Stairwell reported a targeted attack against South Korean journalists using large LNK files and PowerShell to deploy GOLDBACKDOOR. Check Point later cited this as related tradecraft overlapping with later ROKRAT campaigns.
In April 2017, Talos disclosed a spear-phishing campaign targeting South Korean victims with malicious HWP documents exploiting CVE-2013-0808 to deliver ROKRAT. The report described abuse of legitimate services including Twitter, Yandex, and Mediafire for command-and-control and exfiltration.
In March 2025, APT37 conducted a spear-phishing campaign targeting several activists focused on North Korea. The campaign used Dropbox-linked ZIP archives with malicious LNK files that launched hidden PowerShell-based, fileless infection chains culminating in RoKRAT.
A second observed phishing case occurred on March 11, 2025, impersonating an invitation to a national security conference tied to a South Korean think tank event. The lure referenced 'Trump 2.0 Era: Prospects and South Korea’s Response' and delivered a Dropbox link for '관련 포스터.zip,' which contained a harmless JPG and a malicious LNK.
The first observed phishing case in Operation ToyBox Story occurred on March 8, 2025, when APT37 impersonated a North Korea-focused expert in South Korea. The email used the subject '러시아 전장에 투입된 인민군 장병들에게.hwp' and linked to a Dropbox-hosted ZIP archive containing a malicious LNK file.
ASEC reported an ongoing campaign using abnormally large LNK files to target South Korean users, especially people connected to North Korea-related matters. The shortcuts embedded decoy documents, scripts, and PE data, then staged RokRAT from the %public% folder and used pCloud, Yandex, and Dropbox for exfiltration and command-and-control.
ASEC reported that RedEyes, also known as APT37 or ScarCruft, had recently distributed RokRAT through malicious LNK files embedding decoy PDF or HWP content and malicious scripts. The report included file detections, MD5 hashes, and OneDrive-related indicators of compromise tied to the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 109 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegenians.co.kr
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceresearch.checkpoint.com
Open sourceasec.ahnlab.com
Open sourcemandiant.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.