RoKRAT Shellcode and Steganographic Threats: Analysis and EDR Response Strategies
2025-08-03 • Genians •
https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_shellcode_steganographic
Genians identifies a new RoKRAT variant used by APT37 and delivered in South Korea through a compressed archive containing an unusually large malicious LNK file. The shortcut masquerades as a national intelligence and counterintelligence manuscript and embeds a decoy HWP document, shellcode, PowerShell commands, and a batch script. The execution flow runs batch and PowerShell stages that decode shellcode with XOR operations, produce a 32-bit executable, and inject payloads into hardcoded Windows processes such as mspaint.exe, with a later variant switching to notepad.exe. The embedded PDB path containing InjectShellcode, and later a Weapon directory, gives defenders useful variant-tracking evidence while showing continued fileless and shortcut-based tradecraft tied to APT37.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-08-03 | 2026-04-12 | |
| HASH | 443a00feeb3beaea02b2fbcd4302a3c9 | 2025-08-03 | 2026-01-14 |
| HASH | f6d72abf9ca654a20bbaf23ea1c10a55 | 2025-06-09 | 2025-08-29 |
| DOMAIN | cloud-api.yandex.net | 2018-02-27 | 2025-08-29 |
| HASH | d5fe744b9623a0cc7f0ef6464c5530da | 2025-08-03 | 2025-08-03 |
| HASH | 5ed95cde6c29432a4f7dc48602f82734 | 2025-08-03 | 2025-08-03 |
| HASH | fd9099005f133f95a5b699ab30a2f79b | 2025-08-03 | 2025-08-03 |
| HASH | ae7e18a62abb7f93b657276dcae985b9 | 2025-08-03 | 2025-08-03 |
| HASH | e4813c34fe2327de1a94c51e630213d1 | 2025-08-03 | 2025-08-03 |
| HASH | 64d729d0290e2c8ceaa6e38fa68e80e9 | 2025-08-03 | 2025-08-03 |
| HASH | a2ee8d2aa9f79551eb5dd8f9610ad557 | 2025-08-03 | 2025-08-03 |
| HASH | e13c3a38ca58fb0fa9da753e857dd3d5 | 2025-08-03 | 2025-08-03 |
| HASH | 16a8aaaf2e3125668e6bfb1705a065f9 | 2025-08-03 | 2025-08-03 |
| [email protected] | 2025-08-03 | 2025-08-03 | |
| [email protected] | 2025-08-03 | 2025-08-03 | |
| [email protected] | 2025-08-03 | 2025-08-03 |