The evolution of North Korean Android spyware

2023-10-04 0x0v1

https://www.0x0v1.com/the-evolution-of-apt37s-rokrat-rambleon-android-spyware/

Thumbnail for The evolution of North Korean Android spyware

The research traces how APT37-linked Android ROKRAT appears to have evolved into RambleOn, a more capable Android spyware family observed from 2019 through 2023. Early ROKRAT Android samples were described as backdoor or dropper tools, while RambleOn added spyware capabilities such as SMS theft, audio recording, multi-payload operation, and changed command-and-control mechanisms. The analysis cites code similarities between 2017 and 2018 ROKRAT samples and later RambleOn payloads, including cloud-service-based C2 handling and line-for-line code matches. Victim context included South Korean human rights activists and a journalist working on North Korea-related investigations who was asked over WeChat to install a supposed secure chat app.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0dadf1240fd097d15dee890d448cfab… 2023-10-04 2023-10-05
HASH e6a7615d29b287f14ee044cd4e8e786… 2023-10-04 2023-10-05
HASH 748f0724c50bb4e494f8e92e495fa8e… 2023-10-04 2023-10-05
HASH bded85d7024b6cf86cc9ce45ec851c8… 2023-10-04 2023-10-04
HASH 4a45d78b08f4cd62b9c6013adb6140e… 2023-10-04 2023-10-04
HASH 21db3886f23e0829142327e0474349a… 2023-10-04 2023-10-04

Related Actors

Related Reports

« Back