APT37针对韩国外交部下发RokRAT - 安恒威胁情报中心

2023-04-27 • 安恒信息 • APT37 issues RokRAT targeting the Ministry of Foreign Affairs of South Korea - Anheng Threat Intelligence Center •

https://starmap.dbappsecurity.com.cn/blog/articles/2023/04/27/apt37-rokrat/

Thumbnail for APT37针对韩国外交部下发RokRAT - 安恒威胁情报中心

DBAPPSecurity reported APT37 activity against South Korea’s foreign-affairs sector using an ISO image that contained two large padded LNK files. When opened, the LNKs dropped HWP decoys and BAT scripts, then PowerShell downloaded and decrypted the next stage from OneDrive before loading RokRAT. The RokRAT sample used legitimate cloud services, especially pCloud, for command retrieval and supported host reconnaissance, file and process listing, payload download and execution, Windows command execution, and cloud-token updates. The report links the second-stage PowerShell to earlier APT37 tradecraft and notes added encryption in the infection chain to hinder static detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c5c05f9df89fc803884fed2bd20a382… 2023-04-21 2023-05-23
HASH 479894be4c5dec0992ad3c5b21fb142… 2023-04-21 2023-05-23
HASH 6234ef67435dfcb65bd661b5f3bb0b7… 2023-04-27 2023-05-01
HASH 70f9216f0c5badb24120f74270dbbc5… 2023-04-21 2023-05-01
HASH fa4df84071b9ae20b321e4d22162d84… 2023-04-27 2023-04-27

Related Actors

Related Reports

« Back