RoKRAT 셸코드 및 스테가노그래피 기반 위협 분석과 EDR 대응 방안

2025-08-03 Genians RoKRAT shellcode and steganography-based threat analysis and EDR response strategies

https://www.genians.co.kr/blog/threat_intelligence/rokrat_shellcode_steganographic

Thumbnail for RoKRAT 셸코드 및 스테가노그래피 기반 위협 분석과 EDR 대응 방안

Genians analyzes an APT37 RoKRAT campaign in Korea that used oversized LNK files, malicious HWP/OLE content, DLL side-loading, and JPEG steganography to load payloads. One infection chain hides a decoy HWP document, batch script, PowerShell command, and shellcode inside a shortcut, then uses staged XOR decoding to produce a 32-bit RoKRAT executable and inject it into mspaint.exe or notepad.exe. The final RoKRAT module collects host information, documents, and screenshots, then attempts exfiltration through legitimate cloud services including Yandex and Dropbox using cloud API requests and access tokens. The report also documents RoKRAT hidden inside JPEG resources and reinforces the need to monitor external cloud API traffic, script execution, and fileless loader behavior.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-08-03 2026-04-12
HASH 443a00feeb3beaea02b2fbcd4302a3c9 2025-08-03 2026-01-14
HASH f6d72abf9ca654a20bbaf23ea1c10a55 2025-06-09 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29
HASH d5fe744b9623a0cc7f0ef6464c5530da 2025-08-03 2025-08-03
HASH 5ed95cde6c29432a4f7dc48602f82734 2025-08-03 2025-08-03
HASH fd9099005f133f95a5b699ab30a2f79b 2025-08-03 2025-08-03
HASH ae7e18a62abb7f93b657276dcae985b9 2025-08-03 2025-08-03
HASH e4813c34fe2327de1a94c51e630213d1 2025-08-03 2025-08-03
HASH 64d729d0290e2c8ceaa6e38fa68e80e9 2025-08-03 2025-08-03
HASH a2ee8d2aa9f79551eb5dd8f9610ad557 2025-08-03 2025-08-03
HASH e13c3a38ca58fb0fa9da753e857dd3d5 2025-08-03 2025-08-03
HASH 16a8aaaf2e3125668e6bfb1705a065f9 2025-08-03 2025-08-03
EMAIL [email protected] 2025-08-03 2025-08-03
EMAIL [email protected] 2025-08-03 2025-08-03
EMAIL [email protected] 2025-08-03 2025-08-03

Related Actors

Related Reports

« Back