학술논문으로 위장하여 유포 중인 RokRAT 악성코드 주의!
2025-03-27 • ESTSecurity • Warning: RokRAT malware distributed disguised as an academic paper •
ESTsecurity warns that RokRAT malware is being distributed through a malicious LNK file disguised as an academic paper under submission in the defense field. When executed, the shortcut runs embedded PowerShell code, drops a decoy PDF alongside toy01.dat, toy02.dat, and toy03.bat in the user temporary directory, opens the decoy, launches the batch chain, and deletes the original LNK. The report identifies toy01.dat as the encoded RokRAT payload and describes a staged execution flow designed to distract the victim while malware components are unpacked. Defenders should hunt for academic-paper themed LNK lures, PowerShell spawned from shortcuts, toy*.dat or toy*.bat artifacts, and RokRAT-related network or host indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 723f80d1843315717bc56e9e58e89be5 | 2025-03-27 | 2025-05-12 |
| HASH | 46ca088d5c052738d42bbd6231cc0ed5 | 2025-03-27 | 2025-05-12 |
| HASH | 2f431c4e65af9908d2182c6a093bf262 | 2025-03-27 | 2025-05-12 |
| HASH | 5673019b36eca2cb5ce27f206f49b594 | 2025-03-27 | 2025-03-27 |