학술논문으로 위장하여 유포 중인 RokRAT 악성코드 주의!

2025-03-27 ESTSecurity Warning: RokRAT malware distributed disguised as an academic paper

https://alyacofficialblog.tistory.com/5545

Thumbnail for 학술논문으로 위장하여 유포 중인 RokRAT 악성코드 주의!

ESTsecurity warns that RokRAT malware is being distributed through a malicious LNK file disguised as an academic paper under submission in the defense field. When executed, the shortcut runs embedded PowerShell code, drops a decoy PDF alongside toy01.dat, toy02.dat, and toy03.bat in the user temporary directory, opens the decoy, launches the batch chain, and deletes the original LNK. The report identifies toy01.dat as the encoded RokRAT payload and describes a staged execution flow designed to distract the victim while malware components are unpacked. Defenders should hunt for academic-paper themed LNK lures, PowerShell spawned from shortcuts, toy*.dat or toy*.bat artifacts, and RokRAT-related network or host indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 723f80d1843315717bc56e9e58e89be5 2025-03-27 2025-05-12
HASH 46ca088d5c052738d42bbd6231cc0ed5 2025-03-27 2025-05-12
HASH 2f431c4e65af9908d2182c6a093bf262 2025-03-27 2025-05-12
HASH 5673019b36eca2cb5ce27f206f49b594 2025-03-27 2025-03-27

Related Reports

« Back