ATT&CKReferencesMalwarebytes RokRAT VBA January 2021

Malwarebytes RokRAT VBA January 2021

Jazi, Hossein. (2021, January 6). Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat. Retrieved March 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareROKRAT

ROKRAT can collect host data and specific file types.

T1027
Obfuscated Files or Information
MalwareROKRAT

ROKRAT can encrypt data prior to exfiltration by using an RSA public key.

T1033
System Owner/User Discovery
MalwareROKRAT

ROKRAT can collect the username from a compromised host.

T1055
Process Injection
MalwareROKRAT

ROKRAT can use `VirtualAlloc`, `WriteProcessMemory`, and then `CreateRemoteThread` to execute shellcode within the address space of `Notepad.exe`.

T1059.005
Visual Basic
MalwareROKRAT

ROKRAT has used Visual Basic for execution.

T1071.001
Web Protocols
MalwareROKRAT

ROKRAT can use HTTP and HTTPS for command and control communication.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1106
Native API
MalwareROKRAT

ROKRAT can use a variety of API calls to execute shellcode.

T1112
Modify Registry
MalwareROKRAT

ROKRAT can modify the `HKEY_CURRENT_USER\Software\Microsoft\Office\` registry key so it can bypass the VB object model (VBOM) on a compromised host.

T1113
Screen Capture
MalwareROKRAT

ROKRAT can capture screenshots of the infected system using the `gdi32` library.

T1140
Deobfuscate/Decode Files or Information
MalwareROKRAT

ROKRAT can decrypt strings using the victim's hostname as the key.

T1204.002
Malicious File
MalwareROKRAT

ROKRAT has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1497.001
System Checks
MalwareROKRAT

ROKRAT can check for VMware-related files and DLLs related to sandboxes.

T1566.001
Spearphishing Attachment
MalwareROKRAT

ROKRAT has been delivered via spearphishing emails that contain a malicious Hangul Office or Microsoft Word document.

T1567.002
Exfiltration to Cloud Storage
MalwareROKRAT

ROKRAT can send collected data to cloud storage services such as PCloud.

T1622
Debugger Evasion
MalwareROKRAT

ROKRAT can check for debugging tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.