The evolution of North Korean Android spyware
2023-10-04 • 0x0v1 •
https://www.0x0v1.com/the-evolution-of-apt37s-rokrat-rambleon-android-spyware/
The research traces how APT37-linked Android ROKRAT appears to have evolved into RambleOn, a more capable Android spyware family observed from 2019 through 2023. Early ROKRAT Android samples were described as backdoor or dropper tools, while RambleOn added spyware capabilities such as SMS theft, audio recording, multi-payload operation, and changed command-and-control mechanisms. The analysis cites code similarities between 2017 and 2018 ROKRAT samples and later RambleOn payloads, including cloud-service-based C2 handling and line-for-line code matches. Victim context included South Korean human rights activists and a journalist working on North Korea-related investigations who was asked over WeChat to install a supposed secure chat app.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0dadf1240fd097d15dee890d448cfab… | 2023-10-04 | 2023-10-05 |
| HASH | e6a7615d29b287f14ee044cd4e8e786… | 2023-10-04 | 2023-10-05 |
| HASH | 748f0724c50bb4e494f8e92e495fa8e… | 2023-10-04 | 2023-10-05 |
| HASH | bded85d7024b6cf86cc9ce45ec851c8… | 2023-10-04 | 2023-10-04 |
| HASH | 4a45d78b08f4cd62b9c6013adb6140e… | 2023-10-04 | 2023-10-04 |
| HASH | 21db3886f23e0829142327e0474349a… | 2023-10-04 | 2023-10-04 |