Description
ROKRAT is a remote access trojan used against Korean speaking targets, including North Korean defectors and human rights organizations, that abuses legitimate cloud services such as Dropbox, Google Drive, Yandex Disk, and Twitter for command and control. Its use of trusted cloud infrastructure makes its traffic blend into normal user activity.
Stats
- First seen
- April 2024
- Last seen
- September 2026
Also known as
RokratRokratlnk
MITRE ATT&CK techniques
30 techniques across 9 tactics.
TA0002 Execution
TA0005 Stealth
TA0006 Credential Access
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
TA0112 Defense Impairment
- T1112Modify Registry
Associated groups
Alert name variants
| Alert Name |
|---|
| Shortcut.Trojan.Rokratlnk |
| Win32.Spyware.Rokrat |
| Win32.Trojan.Rokratlnk |