APT37组织主战远控武器RokRAT,更新迭代部分执行流程

2024-02-26 qianlan APT37 organizes the main remote control weapon RokRAT and updates and iterates part of the execution process

https://xz.aliyun.com/t/13851?time__1311=mqmxnQG%3DKDu0D%2F%2BG7DyQvfpxGqvDWwD&alichlgref=https%3A%2F%2Fxz.aliyun.com%2Fu%2F80636

The analysis examines a newer RokRAT sample attributed to APT37, also known as Group123, Venus 121, or Reaper, and describes updates to its execution flow. A large LNK lure drops a decoy HWP document plus public.dat, temp.dat, and working.bat, then uses hidden PowerShell to execute shellcode and load an in-memory PE payload. The payload collects system details such as host, user, process path, operating system, BIOS, privilege, and VMware-related information before communicating with api.pcloud.com. The report notes RokRAT's use of public cloud storage services such as pCloud, Dropbox, Yandex, and Box for C2 through embedded tokens and file download, upload, and deletion operations.

Related Actors

Related Reports

« Back