Analysis of ROKRAT Malware inside LNK Malicious file from North Korea

2024-04-03 Plainbit

https://blog.plainbit.co.kr/lnk_rokrat/

Thumbnail for Analysis of ROKRAT Malware inside LNK Malicious file from North Korea

Plainbit analyzes a North Korea-linked RokRAT infection chain delivered in a ZIP archive containing a same-named LNK file disguised as an HWP document. The shortcut runs cmd.exe and PowerShell, hides the command window with user32.dll calls, splits embedded LNK data into a decoy HWP plus public.dat, temp.dat, and working.bat, and deletes the original shortcut. working.bat executes temp.dat as a PowerShell ScriptBlock, which allocates RWX memory with kernel32 APIs, writes public.dat shellcode into memory, and starts a thread to run it. The source provides the extracted command structure and file layout defenders can use to hunt for this LNK-to-PowerShell RokRAT staging pattern.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://content.dropboxapi.com/… 2020-03-25 2025-09-03
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/uploadfi… 2024-04-03 2025-08-29
URL https://cloud-api.yandex.net/v1… 2024-04-03 2025-08-29
URL https://api.pcloud.com/getfilel… 2024-04-03 2025-08-29
URL https://api.pcloud.com/listfold… 2024-04-03 2025-08-29
URL https://api.dropboxapi.com/2/fi… 2023-01-16 2025-08-29
URL https://api.dropboxapi.com/2/fi… 2018-09-21 2025-08-29
URL https://api.pcloud.com/deletefi… 2018-09-21 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29
HASH 5f6682ad9da4590cba106e2f1a8cbe26 2024-03-04 2024-11-04
HASH a1640eb8f424ebe13b94955f8d0f6843 2024-04-03 2024-04-03
HASH 78480139d86520ba82766c5b3c9a7479 2024-04-03 2024-04-03
HASH 31aeb43b981d4d6272193e321bb21333 2024-04-03 2024-04-03
EMAIL [email protected] 2024-04-03 2024-04-03
EMAIL [email protected] 2024-04-03 2024-04-03
EMAIL [email protected] 2024-04-03 2024-04-03
EMAIL [email protected] 2024-04-03 2024-04-03
URL https://cloud-api.yandex.net/v1… 2024-04-03 2024-04-03
DOMAIN goog1e.com 2024-04-03 2024-04-03
DOMAIN dauum.net 2024-04-03 2024-04-03
HASH 7bce02dc0026e271615d4d0e441ca397 2024-03-27 2024-04-03

Related Reports

« Back