logo

North Korean BLUELIGHT Special: InkySquid Deploys RokRAT

ID: 457bc8bc-b65c-5291-b349-c8b87ad68842

STIX ID: report--457bc8bc-b65c-5291-b349-c8b87ad68842

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2021-08-24

Date Updated: 2026-05-01

...
...

Volexity investigated a targeted intrusion against a frequent North Korea target by the InkySquid/APT37 actor that deployed a custom BLUELIGHT loader (via a Python-based scheduled task) and a bespoke RokRAT backdoor (deployed via a Ruby-based loader). Both families use multi-stage, host-specific decryption and cloud-based command-and-control services to evade detection and exfiltrate encrypted data; the report includes technical analysis, IOC hashes, YARA rules, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.