A targeted spearphishing campaign dubbed Operation Capsule Vault used genuine materials from a real academic event to lure researchers, policy workers, and academics into opening malware. Victims were sent a Dropbox link to a malicious ISO image containing a PIF executable disguised as a PDF seminar booklet; when opened, it displayed a legitimate decoy document while silently extracting shellcode and launching a multi-stage loader based on EMBED_PAYLOAD_v2.
The shellcode restored and injected a final x64 RokRAT payload into explorer.exe, where it performed system reconnaissance, file collection, and screen-capture functions while communicating with command-and-control infrastructure over Dropbox, pCloud, and Yandex Cloud. Researchers tied the activity to the broader RokRAT cluster through code similarities, reused cloud-C2 patterns, boundary strings, and reused Yandex OAuth-related infrastructure, and assessed the operation as highly likely linked to APT37.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
In its report, Genians assessed that Operation Capsule Vault was highly likely conducted by APT37. The attribution was based on overlaps with prior RokRAT activity, including reused Yandex infrastructure or tokens, cloud-C2 design, boundary strings, and code similarities with earlier operations.
Genians Security Center analyzed a targeted spear-phishing campaign it named Operation Capsule Vault that used real academic event materials to lure researchers, policy workers, and academics. The attack chain used a Dropbox-hosted ISO containing a PDF-lookalike PIF executable that displayed a decoy document while loading and injecting a RokRAT variant into explorer.exe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcegenians.co.kr
Open sourcegenians.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.