RE:archive | APT37's ROKRAT HWP Object Linking and Embedding

2024-03-01 0x0v1

https://www.0x0v1.com/rearchive-rokrat-hwp/

Thumbnail for RE:archive | APT37's ROKRAT HWP Object Linking and Embedding

A 2022 APT37 sample linked by the author to ROKRAT operations used a malicious Hangul Word Processor document with an embedded OLE object to target a human rights NGO. The lure impersonated South Korea’s Central Election Commission and referenced recruitment for vote-counting observers in the 20th presidential election. When the victim clicked the embedded object, a BAT script launched PowerShell-based reflective DLL injection and loaded a payload in memory from a defanged work3.b4a.app URL, reducing disk artifacts. The excerpt lists the analyzed SHA-256 sample, sender address, an Amazon-hosted stager IP, and a generic Amazon JARM value, while cautioning that the sample is archival rather than evidence of a recent campaign.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 5fec6e533fb9741997530a3d43b60ee… 2024-03-01 2025-02-10
URL https://work3.b4a.app/download.… 2024-03-01 2025-02-10
URL https://work3.b4a.app/download.… 2024-03-01 2025-02-10
URL https://.work3.b4a.app/ 2024-03-01 2025-02-10
EMAIL [email protected] 2024-03-01 2024-04-09
IPv4 52.87.80.2 2024-03-01 2024-03-01

Related Actors

Related Reports

« Back