Reaper Uses New TTPs to Drop RokRAT

2023-05-15 Poly Swarm

https://blog.polyswarm.io/reaper-uses-new-ttps-to-drop-rokrat

Thumbnail for Reaper Uses New TTPs to Drop RokRAT

Reaper, also known as APT37, used newer delivery TTPs to deploy RokRAT against South Korea-focused targets. The campaign delivered ZIP archives containing oversized LNK files masquerading as PDF documents, alongside benign files, through energy-sector and politically themed phishing emails. Opening the LNK displayed a decoy document while PowerShell extracted and ran a BAT script, launched another PowerShell stage, downloaded a C2 payload, and reflectively injected shellcode that decoded and executed RokRAT. The excerpt notes RokRAT’s capabilities for credential theft, data exfiltration, screenshots, system discovery, command and shellcode execution, file management, and Reaper’s continued use of cloud storage services for C2.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0e926d8b6fbf6f14a2a19d4d4af8432… 2023-05-01 2023-10-16
HASH 1e0b5d6b85fca648061fdaf2830c5a9… 2023-05-01 2023-07-04
HASH 6753933cd54e4eba497c48d63c7418a… 2023-05-01 2023-06-26
HASH 240e7bd805bd7f2d17217dd4cebc03a… 2023-05-01 2023-06-06
HASH f92297c4efabba98befeb992a009462… 2023-05-01 2023-06-06
HASH 12ecabf01508c40cfea1ebc39582147… 2023-05-01 2023-05-19
HASH 852607619f1de73d78b4e0de2cc5f37… 2023-05-15 2023-05-15

Related Actors

Related Reports

« Back