Introducing ROKRAT

2017-04-03 Cisco Talos

http://blog.talosintelligence.com/2017/04/introducing-rokrat.html

Thumbnail for Introducing ROKRAT

ROKRAT was delivered through spear-phishing emails carrying malicious HWP documents themed around Korean reunification and North Korea, including one sent through a compromised Yonsei University mail server. The documents embedded EPS objects exploiting CVE-2013-0808 to download disguised .jpg payloads that decoded and executed the RAT. ROKRAT used legitimate services including Twitter, Yandex, and Mediafire for C2, command retrieval, file transfer, and document exfiltration, making network blocking and detection harder in organizations that allow those platforms. The malware supported command execution, file movement and deletion, process killing, download-and-execute behavior, screenshots, and keylogging, while using sandbox and analyst checks to divert execution into fake Amazon and Hulu traffic. The campaign’s Korean-language lures, HWP targeting, and North Korea-related themes show a focused operation against South Korean or Korea-focused victims.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN acddesigns.com.au 2016-11-18 2019-05-14
HASH 051463a14767c6477b6dacd639f30a8… 2017-04-03 2018-01-16
HASH 7d163e36f47ec56c9fe08d758a0770f… 2017-04-03 2018-01-16
HASH cd166565ce09ef410c5bba40bad0b49… 2017-04-03 2018-01-16
HASH 5441f45df22af63498c63a49aae8206… 2017-04-03 2018-01-16
URL http://acddesigns.com.au/client… 2017-04-03 2018-01-16
URL http://discgolfglow.com/wp-cont… 2017-04-03 2018-01-16
URL http://discgolfglow.com:/wp-con… 2017-04-03 2018-01-16
DOMAIN discgolfglow.com 2017-04-03 2018-01-16
EMAIL [email protected] 2017-04-03 2017-04-03
IPv4 165.132.10.103 2017-04-03 2017-04-03

Related Reports

« Back