216.73.217.22

LNK File Disguised as Certificate Distributing RokRAT Malware

· Published 07/05/2024 08:32 · Modified 07/05/2024 08:48

Export JSON

Essential information

Published
07/05/2024 08:32
Modified
07/05/2024 08:48
Tags
2024-05-03 2024-05-04 2024-05-05 2024-05-06 2024-05-07 backdoor lnk rokrat
Related entities
4 observables, 9 techniques (mitre), 1 malware

Description

This analysis delves into the continuous distribution of malicious shortcut files (*.) targeting South Korean users, particularly those related to North Korea. These files contain legitimate documents, script code, and encoded malware data. When executed, they create and run a document file as a decoy, while deploying the malware capable of collecting user information and performing various malicious activities at the threat actor's command using cloud services like pCloud, Yandex, and DropBox. The report provides insights into the operation structure, malicious behaviors, and indicators of compromise associated with this campaign.

External references