Netskope Threat Labs

Drokbk

ATP Sandbox Adv. Heuristics

Drokbk is a backdoor that Cisco Talos researchers linked to Transparent Tribe intrusions against Pakistani government organizations in 2023. It arrives through phishing lures and gives operators command execution and file access on infected Windows systems.

First seen
December 2022
Last seen
September 2026
Alert Name
ByteCode-MSIL.Backdoor.Drokbk
ByteCode-MSIL.Trojan.Drokbk
Win32.Backdoor.Drokbk
Win32.Trojan.Drokbk