HomeSecurityHow does the APT37 group spread the ROKRAT malware?

How does the APT37 group spread the ROKRAT malware?

The North Korean threat actor APT37 has been observed changing its deployment methods and using lures themed around South Korea's external and internal affairs, with files containing Windows shortcut files (LNK) that launch ROKRAT infection chains.

See also: Dish Network likely paid the ransom after recent ransomware attack

APT37 ROKRAT

“Our findings indicate that various multi‑stage infection chains used to load ROKRAT were used in other attacks, leading to the development of additional tools associated with the same threat actor”, explained Check Point Research (CPR) in an advisory published on Monday. “These tools include another custom backdoor, the Goldbackdoor and the malicious commodity software Amadey.”

Security researchers clarified that the ROKRAT infection chains, first identified in 2017, historically involved a malicious Hangul Word Processor (HWP) document with an exploit or a Microsoft Word document with macros.

See also: Facebook: Huge fine due to mishandling of user data

“While some ROKRAT samples continue to use these techniques, we have observed a shift in ROKRAT delivery with LNK files masquerading as legitimate documents”, wrote CPR. “This change is not exclusive to ROKRAT, but represents a larger trend that became very popular in 2022. In July of the same year, Microsoft began blocking macros in Office applications by default, in an effort to minimize the spread of malicious software.”

Technically, ROKRAT primarily focuses on executing additional payloads that are designed for data exfiltration.

“It relies on cloud infrastructure for C&C operations, including DropBox, pCloud, Yandex Cloud, and OneDrive,” CPR wrote in the advisory. “ROKRAT also collects information about the machine to prevent further infection by unwitting victims.”

Additionally, the advisory clarifies that there are reasons why ROKRAT has remained largely unchanged in recent years.

How does the APT37 group spread the ROKRAT malware?

“This can be attributed to the smooth use of in-memory execution, the disguise of C&C communication as potentially legitimate cloud , and additional layers of encryption that prevent network analysis and evade network signatures. As a result, there are not many recently published articles about ROKRAT.”

See also: Cloned CapCut websites spread information-stealing malware

The CPR advisory comes a few days after the warning from Mandiant experts about another APT group associated with North Korea: APT43.

Information source: infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS