ATT&CKReferencesTalos ROKRAT

Talos ROKRAT

Mercer, W., Rascagneres, P. (2017, April 03). Introducing ROKRAT. Retrieved May 21, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareROKRAT

ROKRAT can use the `GetForegroundWindow` and `GetWindowText` APIs to discover where the user is typing.

T1041
Exfiltration Over C2 Channel
MalwareROKRAT

ROKRAT can send collected files back over same C2 channel.

T1056.001
Keylogging
MalwareROKRAT

ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes.

T1057
Process Discovery
MalwareROKRAT

ROKRAT can list the current running processes on the system.

T1071.001
Web Protocols
MalwareROKRAT

ROKRAT can use HTTP and HTTPS for command and control communication.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1102.002
Bidirectional Communication
MalwareROKRAT

ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1113
Screen Capture
MalwareROKRAT

ROKRAT can capture screenshots of the infected system using the `gdi32` library.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.