CHAIN REACTION: ROKRAT’S MISSING LINK

2023-05-01 Checkpoint

https://research.checkpoint.com/2023/chain-reaction-rokrats-missing-link/

Thumbnail for CHAIN REACTION: ROKRAT’S MISSING LINK

Check Point tracks APT37-linked ROKRAT activity shifting from older HWP exploits and Office macros toward ZIP or ISO archives containing oversized LNK files that launch multi-stage infection chains. The lures focus heavily on South Korean domestic and foreign affairs, with examples tied to National Assembly committee lists, North Korea diplomacy, and Korean-speaking targets, while one English-language case used Libyan oil and gas project documents involving a South Korean consultant. Several chains were observed leading to ROKRAT, and related tooling or overlapping chains included GOLDBACKDOOR and the commodity Amadey RAT. The report emphasizes that ROKRAT remains actively developed across Windows, macOS, and Android variants and that its cloud-service-based command-and-control and macro-blocking-era LNK delivery tradecraft remain important for tracking APT37 operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0e926d8b6fbf6f14a2a19d4d4af8432… 2023-05-01 2023-10-16
HASH 5a3f1d14b9cc4890db64fbc41818d70… 2023-05-01 2023-10-16
DOMAIN naver-file.com 2023-05-01 2023-10-16
DOMAIN naver-storage.com 2023-05-01 2023-09-26
DOMAIN daum-store.com 2023-05-01 2023-09-26
DOMAIN nate-download.com 2023-05-01 2023-09-26
URL https://1drv.ms/u/s!AhQMP6eg8aR… 2023-05-01 2023-09-25
URL https://1drv.ms/u/s!AjQNLvEE_CU… 2023-05-01 2023-07-13
URL https://api.onedrive.com/v1.0/s… 2023-05-01 2023-07-13
HASH 1e0b5d6b85fca648061fdaf2830c5a9… 2023-05-01 2023-07-04
URL https://1drv.ms/i/s!AhXEXLJSNMP… 2023-04-21 2023-07-04
HASH 6753933cd54e4eba497c48d63c7418a… 2023-05-01 2023-06-26
HASH cb4c7037c7620e4ce3f8f43161b0ec6… 2023-05-01 2023-06-06
HASH 240e7bd805bd7f2d17217dd4cebc03a… 2023-05-01 2023-06-06
HASH f92297c4efabba98befeb992a009462… 2023-05-01 2023-06-06
HASH 06431a5d8f6262cc3db39d911a920f7… 2023-05-01 2023-06-06
HASH 1c5b9409243bfb81a5924881cc05f63… 2023-05-01 2023-06-06
HASH 00d88009fa50bfab849593291cce20f… 2023-05-01 2023-06-06
URL https://1drv.ms/u/s!Au2my1xh6t8… 2023-04-21 2023-06-06
HASH 12ecabf01508c40cfea1ebc39582147… 2023-05-01 2023-05-19
URL https://1drv.ms/u/s!Au2my1xh6t8… 2023-05-01 2023-05-19
HASH 6234ef67435dfcb65bd661b5f3bb0b7… 2023-05-01 2023-05-01
HASH 050c65d45e5f21018aa940f0188c4aa… 2023-05-01 2023-05-01
HASH c5c05f9df89fc803884fed2bd20a382… 2023-05-01 2023-05-01
HASH 70f9216f0c5badb24120f74270dbbc5… 2023-05-01 2023-05-01
HASH eb03f8b8e41b3ad27ccdecb092111e2… 2023-05-01 2023-05-01
HASH 9a4c61cdf0e291dc364c568aa161f74… 2023-05-01 2023-05-01
HASH c4029a2f1d0c07ae2b388b5a4076fba… 2023-05-01 2023-05-01
HASH 732fca9be66ba2c40c5d05845540207… 2023-05-01 2023-05-01
HASH 479894be4c5dec0992ad3c5b21fb142… 2023-05-01 2023-05-01
DOMAIN 1erluw.bl.files.1drv.com 2023-05-01 2023-05-01
DOMAIN u9izog.dm.files.1drv.com 2023-05-01 2023-05-01
DOMAIN qb3oaq.bl.files.1drv.com 2023-05-01 2023-05-01
HASH 3252345b2640efc44cdd98667dbd258… 2023-04-10 2023-05-01

Related Actors

Related Reports

« Back