Security researchers linked a new ROKRAT malware variant to the FreeMilk intrusion set after finding shared reconnaissance code, similar PDB path patterns, overlapping credential-theft functionality, and ties to the Freenki downloader. Cisco Talos said the ROKRAT sample was delivered through a malicious Hangul Word Processor (HWP) document themed around North Korean human rights and Korean reunification, then dropped c:\ProgramData\HncModuleUpdate.exe, injected shellcode into cmd.exe, and loaded the payload in memory. The malware used legitimate cloud services for command-and-control and included anti-sandbox, anti-debugging, screenshot capture, and browser credential theft targeting Internet Explorer, Chrome, and Firefox.
Palo Alto Networks Unit 42 had previously described FreeMilk as a highly targeted spear-phishing operation that hijacked legitimate email threads and exploited CVE-2017-0199 to infect selected victims with PoohMilk and Freenki. The campaign targeted organizations including a Middle Eastern bank, European trademark and intellectual property firms, an international sporting organization, and individuals with indirect ties to a country in Northeast Asia. Researchers said the actor emphasized stealth through customized decoy documents, required command-line arguments for malware execution, and showed links to earlier N1stAgent activity and a 2016 watering-hole attack, strengthening the assessment that the same actor or closely cooperating operators were behind both the ROKRAT and FreeMilk campaigns.

Get the infrastructure and lures behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Volexity investigated a targeted compromise attributed to APT37/InkySquid in which attackers deployed the BLUELIGHT malware followed less than 10 minutes later by a customized RokRAT payload. The intrusion used Python- and Ruby-based scheduled-task loaders and cloud services including PCloud, Yandex, Dropbox, and Box for command and control and encrypted data exfiltration.
A malicious Microsoft Office document compiled in January 2020 was likely used to spear-phish South Korean government targets and deliver a RokRat variant attributed to APT37. The document used a VBA self-decoding macro, modified the VBOM registry setting if needed, injected shellcode into Notepad.exe, and downloaded the payload from a bit.ly link redirecting to Google Drive.
Talos found the November 2017 ROKRAT variant shared reconnaissance code, PDB path patterns, and browser credential theft code with earlier Evil New Years, FreeMilk, and Freenki activity, reinforcing that the same actor or closely cooperating actors were behind the operations.
Cisco Talos discovered a new version of ROKRAT in November 2017 delivered through a malicious Hangul Word Processor document targeting people interested in North Korea-related policy and human rights topics in South Korea.
The malicious HWP decoy used in the later ROKRAT campaign referenced a meeting in Seoul dated 1 November 2017 and was themed around North Korean human rights and reunification issues.
Unit 42 reported that PoohMilk was also used to deliver another malware family, N1stAgent, in June 2017, extending the activity associated with the same tooling.
Palo Alto Networks Unit 42 identified a limited spear-phishing campaign in May 2017 and named it FreeMilk. The campaign hijacked legitimate email threads and exploited CVE-2017-0199 to deliver the PoohMilk loader and Freenki downloader to selected victims worldwide.
Cisco Talos publicly introduced the ROKRAT malware family in a blog post, marking an earlier documented stage of the campaign before the later November 2017 variant. This establishes ROKRAT activity as known by April 2017.
Unit 42 linked the Freenki malware to an August 2016 watering-hole attack that exploited CVE-2016-0189 on an anti-government media website operated by defectors in the United Kingdom.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 40 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
volexity.com
Open sourceblog.malwarebytes.com
Open sourceattack.mitre.org
Open sourceblog.talosintelligence.com
Open sourceblog.talosintelligence.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourceresearch.nccgroup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.