Reaper Uses New TTPs to Drop RokRAT
2023-05-15 • Poly Swarm •
https://blog.polyswarm.io/reaper-uses-new-ttps-to-drop-rokrat
Reaper, also known as APT37, used newer delivery TTPs to deploy RokRAT against South Korea-focused targets. The campaign delivered ZIP archives containing oversized LNK files masquerading as PDF documents, alongside benign files, through energy-sector and politically themed phishing emails. Opening the LNK displayed a decoy document while PowerShell extracted and ran a BAT script, launched another PowerShell stage, downloaded a C2 payload, and reflectively injected shellcode that decoded and executed RokRAT. The excerpt notes RokRAT’s capabilities for credential theft, data exfiltration, screenshots, system discovery, command and shellcode execution, file management, and Reaper’s continued use of cloud storage services for C2.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0e926d8b6fbf6f14a2a19d4d4af8432… | 2023-05-01 | 2023-10-16 |
| HASH | 1e0b5d6b85fca648061fdaf2830c5a9… | 2023-05-01 | 2023-07-04 |
| HASH | 6753933cd54e4eba497c48d63c7418a… | 2023-05-01 | 2023-06-26 |
| HASH | 240e7bd805bd7f2d17217dd4cebc03a… | 2023-05-01 | 2023-06-06 |
| HASH | f92297c4efabba98befeb992a009462… | 2023-05-01 | 2023-06-06 |
| HASH | 12ecabf01508c40cfea1ebc39582147… | 2023-05-01 | 2023-05-19 |
| HASH | 852607619f1de73d78b4e0de2cc5f37… | 2023-05-15 | 2023-05-15 |