logo

North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor

ID: cf441394-302a-54bf-989a-745bcec4f41a

STIX ID: report--cf441394-302a-54bf-989a-745bcec4f41a

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-01-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

SentinelOne researchers attribute a December 2023 campaign to North Korea–linked ScarCruft (APT37) that targeted media and North Korea experts by delivering ZIP files containing benign decoys alongside malicious LNK files and shellcode to stage the RokRAT backdoor; the actor used a legitimate threat-intelligence report as a decoy and appears to be experimenting with new infection chains and brand-impersonation techniques to refine targeting and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.