logo

APT37__2021__blog.malwarebytes.com-Retrohunting_APT37_North_Korean_APT_used_VBA_self_decode_technique_to_inject_RokRat.pdf

ID: 0b45f8d0-a771-440f-b548-e495fbbc0a2a

STIX ID: report--0b45f8d0-a771-440f-b548-e495fbbc0a2a

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2021-01-07

Last Modified Date: 2021-01-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malwarebytes Threat Intelligence details a spearphishing campaign attributed to North Korea's APT37 that weaponized a Microsoft Word document using a VBA self-decoding macro to unpack and execute a payload in memory, injecting a variant of the RokRat remote access Trojan into Notepad; the report provides step‑by‑step macro and shellcode analysis, anti‑analysis checks, RokRat capabilities (credential theft, screenshots, cloud-based exfiltration), and IOCs including hashes and the download URL.