ATT&CKReferencesVolexity InkySquid RokRAT August 2021

Volexity InkySquid RokRAT August 2021

Cash, D., Grunzweig, J., Adair, S., Lancaster, T. (2021, August 25). North Korean BLUELIGHT Special: InkySquid Deploys RokRAT. Retrieved October 1, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareROKRAT

ROKRAT can collect host data and specific file types.

T1027
Obfuscated Files or Information
MalwareROKRAT

ROKRAT can encrypt data prior to exfiltration by using an RSA public key.

T1027
Obfuscated Files or Information
GroupAPT37

APT37 obfuscates strings and payloads.

T1053.005
Scheduled Task
GroupAPT37

APT37 has created scheduled tasks to run malicious scripts on a compromised host.

T1056.001
Keylogging
MalwareROKRAT

ROKRAT can use `SetWindowsHookEx` and `GetKeyNameText` to capture keystrokes.

T1059
Command and Scripting Interpreter
GroupAPT37

APT37 has used Ruby scripts to execute payloads.

T1059.006
Python
GroupAPT37

APT37 has used Python scripts to execute payloads.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1083
File and Directory Discovery
MalwareROKRAT

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1102.002
Bidirectional Communication
MalwareROKRAT

ROKRAT has used legitimate social networking sites and cloud platforms (including but not limited to Twitter, Yandex, Dropbox, and Mediafire) for C2 communications.

T1105
Ingress Tool Transfer
GroupAPT37

APT37 has downloaded second stage malware from compromised websites.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1115
Clipboard Data
MalwareROKRAT

ROKRAT can extract clipboard data from a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareROKRAT

ROKRAT can decrypt strings using the victim's hostname as the key.

T1480.001
Environmental Keying
MalwareROKRAT

ROKRAT relies on a specific victim hostname to execute and decrypt important strings.

T1567.002
Exfiltration to Cloud Storage
MalwareROKRAT

ROKRAT can send collected data to cloud storage services such as PCloud.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.