#CapsuleVault

Incident/Operation

2026-07-12 • Operation Capsule Vault: EMBED_PAYLOAD_v2 기반 RokRAT 공격 체인 분석

CapsuleVault is a June 2026 spear-phishing operation assessed with high likelihood to have been conducted by APT37 against researchers, policy specialists, and academics. The campaign impersonated distribution of materials from a real conference and redirected recipients to an ISO image containing a PIF executable disguised as a PDF. Its EMBED_PAYLOAD_v2 loader opened a legitimate decoy while decrypting shellcode that injected an x64 RokRAT variant into Explorer; RokRAT then used legitimate cloud services for command-and-control, system reconnaissance, screenshots, file collection, command execution, and additional payload delivery.

Tagged Reports

« Back