216.73.217.22

APT37 - RokRat

· Published 12/03/2025 11:56 · Modified 12/03/2025 12:25

Export JSON

Essential information

Published
12/03/2025 11:56
Modified
12/03/2025 12:25
Tags
2025-03-12 cloud services lnk files north korea phishing powershell remote access trojan rokrat
Related entities
9 observables, 1 intrusion sets (apt), 21 techniques (mitre), 1 malware, 3 others

Description

APT37, a North Korean state-sponsored hacking group, has expanded its operations to target users on Windows and Android platforms through campaigns. The group's attack vector involves malicious distributed via group chat platforms. The infection process begins with emails containing ZIP attachments that conceal malicious . When executed, these files initiate a multi-stage attack using batch scripts and , ultimately deploying as the final payload. , a , collects detailed system information, abuses for command and control, and employs anti-analysis techniques. It can execute remote commands, exfiltrate data, and perform various malicious activities on infected systems.

External references