#CapsuleVault
Incident/Operation
2026-07-12 • Operation Capsule Vault: EMBED_PAYLOAD_v2 기반 RokRAT 공격 체인 분석
CapsuleVault is a June 2026 spear-phishing operation assessed with high likelihood to have been conducted by APT37 against researchers, policy specialists, and academics. The campaign impersonated distribution of materials from a real conference and redirected recipients to an ISO image containing a PIF executable disguised as a PDF. Its EMBED_PAYLOAD_v2 loader opened a legitimate decoy while decrypting shellcode that injected an x64 RokRAT variant into Explorer; RokRAT then used legitimate cloud services for command-and-control, system reconnaissance, screenshots, file collection, command execution, and additional payload delivery.
-
2
Tagged Reports
-
1
Unique Authors
-
1
Active Days