TGViewer
cKure Red cKure Red @ckured · 2.78K subscribers
Post #638 1.55K
🎃HOW APT37 EMPLOYED ROKRAT SHELLCODE AND STEGANOGRAPHIC TECHNIQUE

ℹ️ Researchers have identified a new variant of RoKRAT, the malware associated with North Korea’s APT37 group. This version employs two-stage encrypted shellcode execution and steganography to conceal malicious code inside image files, enabling evasion from traditional detection methods.

📍 INFECTION VECTOR
■ The intrusion begins with a ZIP archive containing a large .lnk shortcut file, often masquerading as legitimate documents.
■ Once opened, PowerShell commands embedded within the shortcut unpack multiple hidden components, such as shellcode, batch files, scripts, and decoy documents, and launch the infection chain.

📍TWO-STAGE SHELLCODE DECODING
■ The initial embedded shellcode is decoded using a single-byte XOR, then injected into a trusted Windows process like mspaint.exe or notepad[.]exe.
■ A second stage of XOR-based decoding (e.g. key 0xD6) reveals the full RoKRAT payload, which is executed entirely in memory without writing to disk.

📍 STEGANOGRAPHIC PAYLOAD DELIVERY
■ The standout feature of this variant is the use of steganography: a JPEG image (e.g. "Father.jpg") is downloaded from cloud services (Dropbox, Yandex, pCloud) and contains encrypted shellcode starting at a non-standard offset.
■ A dual XOR decoding process transforms this hidden data into an executable loader, which initiates RoKRAT in-memory execution without leaving disk artifacts

📍 C2 COMMUNICATION & TARGETS
■ RoKRAT communicates with C2 infrastructure via legitimate cloud APIs using expired or stolen tokens tied to Dropbox, pCloud, and Yandex.
■ The malware collects system info, documents, screenshots, and exfiltrates data in encrypted form, disguised within normal traffic to bypass inspection.


https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_shellcode_steganographic
More from @ckured
  1. Oct 3, 2026Update: Archivegenocide has now crossed 200,000 videos & images, which is almost triple wh…
  2. Sep 29, 2026📱 Telegram OSINT tactics
  3. Sep 26, 2026☁️ Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops…
  4. Sep 23, 2026Alleged Google Pixel 10 Zero Day at 2.5K USD only as chain included some n-days. An intere…
  5. Sep 18, 2026AliExpress spyware caught using side channel attack to compromise hardware.
  6. Sep 17, 2026😒 Claude Code was used to make missile guidance system for 9 months by Houthis using mult…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →