ROKRAT

S0240

Malware.View on attack.mitre.org

About this malware

ROKRAT is a cloud-based remote access tool (RAT) used by APT37 to target victims in South Korea. APT37 has used ROKRAT during several campaigns from 2016 through 2021.

Techniques used30

Procedure examples30

TechniqueProcedure example
T1005
Data from Local System

ROKRAT can collect host data and specific file types.

T1010
Application Window Discovery

ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing.

T1012
Query Registry

ROKRAT can access the HKLM\System\CurrentControlSet\Services\mssmbios\Data\SMBiosData Registry key to obtain the System manufacturer value to identify the machine type.

T1027
Obfuscated Files or Information

ROKRAT can encrypt data prior to exfiltration by using an RSA public key.

T1033
System Owner/User Discovery

ROKRAT can collect the username from a compromised host.

T1041
Exfiltration Over C2 Channel

ROKRAT can send collected files back over same C2 channel.

T1055
Process Injection

ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`.

T1056.001
Keylogging

ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes.

T1057
Process Discovery

ROKRAT can list the current running processes on the system.

T1059.005
Visual Basic

ROKRAT has used Visual Basic for execution.

T1070.004
File Deletion

ROKRAT can request to delete files.

T1071.001
Web Protocols

ROKRAT can use HTTP and HTTPS for command and control communication.

T1082
System Information Discovery

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1083
File and Directory Discovery

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1102.002
Bidirectional Communication

ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications.

View all 30 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Talos Group123 Open source
    Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.
  2. Talos ROKRAT Open source
    Mercer, W., Rascagneres, P. (2017, April 03). Introducing ROKRAT. Retrieved May 21, 2018.
  3. Volexity InkySquid RokRAT August 2021 Open source
    Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.