Introducing ROKRAT
2017-04-03 • Cisco Talos •
http://blog.talosintelligence.com/2017/04/introducing-rokrat.html
ROKRAT was delivered through spear-phishing emails carrying malicious HWP documents themed around Korean reunification and North Korea, including one sent through a compromised Yonsei University mail server. The documents embedded EPS objects exploiting CVE-2013-0808 to download disguised .jpg payloads that decoded and executed the RAT. ROKRAT used legitimate services including Twitter, Yandex, and Mediafire for C2, command retrieval, file transfer, and document exfiltration, making network blocking and detection harder in organizations that allow those platforms. The malware supported command execution, file movement and deletion, process killing, download-and-execute behavior, screenshots, and keylogging, while using sandbox and analyst checks to divert execution into fake Amazon and Hulu traffic. The campaign’s Korean-language lures, HWP targeting, and North Korea-related themes show a focused operation against South Korean or Korea-focused victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | acddesigns.com.au | 2016-11-18 | 2019-05-14 |
| HASH | 051463a14767c6477b6dacd639f30a8… | 2017-04-03 | 2018-01-16 |
| HASH | 7d163e36f47ec56c9fe08d758a0770f… | 2017-04-03 | 2018-01-16 |
| HASH | cd166565ce09ef410c5bba40bad0b49… | 2017-04-03 | 2018-01-16 |
| HASH | 5441f45df22af63498c63a49aae8206… | 2017-04-03 | 2018-01-16 |
| URL | http://acddesigns.com.au/client… | 2017-04-03 | 2018-01-16 |
| URL | http://discgolfglow.com/wp-cont… | 2017-04-03 | 2018-01-16 |
| URL | http://discgolfglow.com:/wp-con… | 2017-04-03 | 2018-01-16 |
| DOMAIN | discgolfglow.com | 2017-04-03 | 2018-01-16 |
| [email protected] | 2017-04-03 | 2017-04-03 | |
| IPv4 | 165.132.10.103 | 2017-04-03 | 2017-04-03 |