RoKRAT Shellcode and Steganographic Threats: Analysis and EDR Response Strategies

2025-08-03 Genians

https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_shellcode_steganographic

Thumbnail for RoKRAT Shellcode and Steganographic Threats: Analysis and EDR Response Strategies

Genians identifies a new RoKRAT variant used by APT37 and delivered in South Korea through a compressed archive containing an unusually large malicious LNK file. The shortcut masquerades as a national intelligence and counterintelligence manuscript and embeds a decoy HWP document, shellcode, PowerShell commands, and a batch script. The execution flow runs batch and PowerShell stages that decode shellcode with XOR operations, produce a 32-bit executable, and inject payloads into hardcoded Windows processes such as mspaint.exe, with a later variant switching to notepad.exe. The embedded PDB path containing InjectShellcode, and later a Weapon directory, gives defenders useful variant-tracking evidence while showing continued fileless and shortcut-based tradecraft tied to APT37.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-08-03 2026-04-12
HASH 443a00feeb3beaea02b2fbcd4302a3c9 2025-08-03 2026-01-14
HASH f6d72abf9ca654a20bbaf23ea1c10a55 2025-06-09 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29
HASH d5fe744b9623a0cc7f0ef6464c5530da 2025-08-03 2025-08-03
HASH 5ed95cde6c29432a4f7dc48602f82734 2025-08-03 2025-08-03
HASH fd9099005f133f95a5b699ab30a2f79b 2025-08-03 2025-08-03
HASH ae7e18a62abb7f93b657276dcae985b9 2025-08-03 2025-08-03
HASH e4813c34fe2327de1a94c51e630213d1 2025-08-03 2025-08-03
HASH 64d729d0290e2c8ceaa6e38fa68e80e9 2025-08-03 2025-08-03
HASH a2ee8d2aa9f79551eb5dd8f9610ad557 2025-08-03 2025-08-03
HASH e13c3a38ca58fb0fa9da753e857dd3d5 2025-08-03 2025-08-03
HASH 16a8aaaf2e3125668e6bfb1705a065f9 2025-08-03 2025-08-03
EMAIL [email protected] 2025-08-03 2025-08-03
EMAIL [email protected] 2025-08-03 2025-08-03
EMAIL [email protected] 2025-08-03 2025-08-03

Related Actors

Related Reports

« Back