학술논문으로 위장하여 유포 중인 RokRAT 악성코드 주의!

2025-03-27 ESTSecurity Warning: RokRAT malware distributed disguised as an academic paper

https://alyacofficialblog.tistory.com/5545

Thumbnail for 학술논문으로 위장하여 유포 중인 RokRAT 악성코드 주의!

ESTsecurity warns that RokRAT malware is being distributed through a malicious LNK file disguised as an academic paper under submission in the defense field. When executed, the shortcut runs embedded PowerShell code, drops a decoy PDF alongside toy01.dat, toy02.dat, and toy03.bat in the user temporary directory, opens the decoy, launches the batch chain, and deletes the original LNK. The report identifies toy01.dat as the encoded RokRAT payload and describes a staged execution flow designed to distract the victim while malware components are unpacked. Defenders should hunt for academic-paper themed LNK lures, PowerShell spawned from shortcuts, toy*.dat or toy*.bat artifacts, and RokRAT-related network or host indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 92ab3a9040f5e620bc4b76295239c52… 2025-03-27 2025-05-12
HASH 9b8218774c3abc0a449cfc490f12e81… 2025-03-27 2025-05-12
HASH d182834a984c9f5b44ea0aca5786223… 2025-03-27 2025-05-12
HASH dddea9676818804c266cce208350af5… 2025-03-27 2025-03-27

Related Reports

« Back