RoKRAT 셸코드 및 스테가노그래피 기반 위협 분석과 EDR 대응 방안
2025-08-03 • Genians • RoKRAT shellcode and steganography-based threat analysis and EDR response strategies •
https://www.genians.co.kr/blog/threat_intelligence/rokrat_shellcode_steganographic
Genians analyzes an APT37 RoKRAT campaign in Korea that used oversized LNK files, malicious HWP/OLE content, DLL side-loading, and JPEG steganography to load payloads. One infection chain hides a decoy HWP document, batch script, PowerShell command, and shellcode inside a shortcut, then uses staged XOR decoding to produce a 32-bit RoKRAT executable and inject it into mspaint.exe or notepad.exe. The final RoKRAT module collects host information, documents, and screenshots, then attempts exfiltration through legitimate cloud services including Yandex and Dropbox using cloud API requests and access tokens. The report also documents RoKRAT hidden inside JPEG resources and reinforces the need to monitor external cloud API traffic, script execution, and fileless loader behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-08-03 | 2026-04-12 | |
| HASH | 443a00feeb3beaea02b2fbcd4302a3c9 | 2025-08-03 | 2026-01-14 |
| HASH | f6d72abf9ca654a20bbaf23ea1c10a55 | 2025-06-09 | 2025-08-29 |
| DOMAIN | cloud-api.yandex.net | 2018-02-27 | 2025-08-29 |
| HASH | d5fe744b9623a0cc7f0ef6464c5530da | 2025-08-03 | 2025-08-03 |
| HASH | 5ed95cde6c29432a4f7dc48602f82734 | 2025-08-03 | 2025-08-03 |
| HASH | fd9099005f133f95a5b699ab30a2f79b | 2025-08-03 | 2025-08-03 |
| HASH | ae7e18a62abb7f93b657276dcae985b9 | 2025-08-03 | 2025-08-03 |
| HASH | e4813c34fe2327de1a94c51e630213d1 | 2025-08-03 | 2025-08-03 |
| HASH | 64d729d0290e2c8ceaa6e38fa68e80e9 | 2025-08-03 | 2025-08-03 |
| HASH | a2ee8d2aa9f79551eb5dd8f9610ad557 | 2025-08-03 | 2025-08-03 |
| HASH | e13c3a38ca58fb0fa9da753e857dd3d5 | 2025-08-03 | 2025-08-03 |
| HASH | 16a8aaaf2e3125668e6bfb1705a065f9 | 2025-08-03 | 2025-08-03 |
| [email protected] | 2025-08-03 | 2025-08-03 | |
| [email protected] | 2025-08-03 | 2025-08-03 | |
| [email protected] | 2025-08-03 | 2025-08-03 |