Analysis of ROKRAT Malware inside LNK Malicious file from North Korea
2024-04-03 • Plainbit •
Plainbit analyzes a North Korea-linked RokRAT infection chain delivered in a ZIP archive containing a same-named LNK file disguised as an HWP document. The shortcut runs cmd.exe and PowerShell, hides the command window with user32.dll calls, splits embedded LNK data into a decoy HWP plus public.dat, temp.dat, and working.bat, and deletes the original shortcut. working.bat executes temp.dat as a PowerShell ScriptBlock, which allocates RWX memory with kernel32 APIs, writes public.dat shellcode into memory, and starts a thread to run it. The source provides the extracted command structure and file layout defenders can use to hunt for this LNK-to-PowerShell RokRAT staging pattern.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://content.dropboxapi.com/… | 2020-03-25 | 2025-09-03 |
| URL | https://content.dropboxapi.com/… | 2018-09-21 | 2025-09-03 |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2025-08-29 |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2025-08-29 |
| URL | https://api.pcloud.com/uploadfi… | 2024-04-03 | 2025-08-29 |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2025-08-29 |
| URL | https://api.pcloud.com/getfilel… | 2024-04-03 | 2025-08-29 |
| URL | https://api.pcloud.com/listfold… | 2024-04-03 | 2025-08-29 |
| URL | https://api.dropboxapi.com/2/fi… | 2023-01-16 | 2025-08-29 |
| URL | https://api.dropboxapi.com/2/fi… | 2018-09-21 | 2025-08-29 |
| URL | https://api.pcloud.com/deletefi… | 2018-09-21 | 2025-08-29 |
| DOMAIN | cloud-api.yandex.net | 2018-02-27 | 2025-08-29 |
| HASH | 5f6682ad9da4590cba106e2f1a8cbe26 | 2024-03-04 | 2024-11-04 |
| HASH | a1640eb8f424ebe13b94955f8d0f6843 | 2024-04-03 | 2024-04-03 |
| HASH | 78480139d86520ba82766c5b3c9a7479 | 2024-04-03 | 2024-04-03 |
| HASH | 31aeb43b981d4d6272193e321bb21333 | 2024-04-03 | 2024-04-03 |
| [email protected] | 2024-04-03 | 2024-04-03 | |
| [email protected] | 2024-04-03 | 2024-04-03 | |
| [email protected] | 2024-04-03 | 2024-04-03 | |
| [email protected] | 2024-04-03 | 2024-04-03 | |
| URL | https://cloud-api.yandex.net/v1… | 2024-04-03 | 2024-04-03 |
| DOMAIN | goog1e.com | 2024-04-03 | 2024-04-03 |
| DOMAIN | dauum.net | 2024-04-03 | 2024-04-03 |
| HASH | 7bce02dc0026e271615d4d0e441ca397 | 2024-03-27 | 2024-04-03 |