logo

LNK File Disguised as Certificate Distributing RokRAT Malware

ID: 1431e81f-b226-546c-8812-44d3e11c2686

STIX ID: report--1431e81f-b226-546c-8812-44d3e11c2686

Feed Name: ASEC

Threat Score
78/100

Date Published: 2024-05-07

Date Updated: 2026-04-26

Author: yeeun

...
...

ASEC reports an active campaign targeting South Korean users with malicious .LNK shortcut files that execute PowerShell to extract embedded payloads and deploy the RokRAT backdoor (fileless execution via viewer.dat/search.dat/find.bat). The malware collects system and user information, can execute commands and delete startup items, and exfiltrates data to cloud storage services (pCloud, Yandex, Dropbox) using a Googlebot-disguised User-Agent; the report includes filenames, MD5 hashes, and threat actor email addresses as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.