Operation Capsule Vault: Analysis of a RokRAT Attack Chain Using EMBED_PAYLOAD_v2

Summary
Genians analyzed a spear-phishing campaign that delivered RokRAT through a PDF-disguised PIF inside a Dropbox-hosted ISO. The multi-stage loader used shellcode and process injection; researchers assess APT37 was highly likely responsible.
Key points
- Spear-phishing emails impersonated materials from a real academic event and targeted people in research, policy, and academic fields.
- A Dropbox link delivered an ISO containing a PIF executable disguised as a PDF; the file displayed a decoy document while running malicious code.
- The EMBED_PAYLOAD_v2 loader extracted embedded shellcode, decrypted a payload in memory, and injected it into explorer.exe.
- The injected RokRAT variant supports cloud C2 through pCloud, Dropbox, and Yandex and can collect system information, screenshots, drive listings, and files, as well as execute commands.
- Genians assesses APT37 was highly likely responsible, citing code and infrastructure overlaps with previously analyzed RokRAT activity, while noting code similarity alone cannot establish attribution.
- Defenders should correlate phishing, ISO and PIF execution, process injection, memory activity, and cloud C2 behavior; the report also provides IOC IP addresses.
Article Details
- Attack Vectors
- Spear-phishing emails sent on 2026-06-22 impersonated the distribution of materials from an actual academic event and linked to a malicious ISO image hosted on Dropbox.
- The ISO contained a PIF executable disguised with a PDF-like filename and icon. Execution displayed a legitimate-looking PDF while extracting an embedded shellcode payload.
- The loader decoded the payload in memory and injected a RokRAT variant into explorer.exe.
- RokRAT used cloud-service APIs for command retrieval and data upload, and supported remote command execution, file collection, screen capture, and execution of additional payloads.
- Defensive Notes
- Correlate spear-phishing delivery, ISO downloads, and execution of PDF-disguised PIF files, including double-extension filenames.
- Monitor PIF-initiated memory allocation, writes into explorer.exe, remote-thread creation, and subsequent cloud-service connections.
- Use EDR behavior and network telemetry together to trace the attack chain rather than relying only on file signatures or isolated network events.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
johnson8903013@gmail[.]com | Listed by Genians among indicators associated with the threat actor's spear-phishing activity and attack infrastructure. | |
| IPV4 | 160[.]238[.]37[.]100 | Listed as an attack-related IP indicator; identified as a Nord VPN exit node. |
| IPV4 | 160[.]238[.]37[.]95 | Listed as an attack-related IP indicator; identified as a Nord VPN exit node. |
| IPV4 | 5[.]180[.]208[.]57 | Listed as an IP indicator used in the threat actor's spear-phishing activity or attack infrastructure. |
| IPV4 | 5[.]180[.]208[.]60 | Listed as an IP indicator used in the threat actor's spear-phishing activity or attack infrastructure. |
| IPV4 | 89[.]147[.]101[.]197 | Listed as an attack-related IP indicator; identified as a Nord VPN exit node. |
| IPV4 | 89[.]187[.]161[.]220 | Listed as an attack-related IP indicator; identified as an Astrill VPN exit node. |
| MD5 | e5c9bb3938f2a24e755ee39073fc3aca | Malicious-file hash published in the report's IoC section. |
MITRE ATT&CK
T1027.009 · Embedded PayloadsThe PIF loader stored a decoy PDF and a shellcode binary in an EMBED_PAYLOAD_v2 embedded payload table.T1036.007 · Double File ExtensionThe malicious executable used a PDF-like filename ending in .pdf.pif to conceal its executable extension.T1041 · Exfiltration Over C2 ChannelRokRAT uploaded collected files, system information, and screen captures through its cloud C2 communication.T1055 · Process InjectionThe loader wrote the restored payload into explorer.exe and started it through a remote thread.T1057 · Process DiscoveryRokRAT enumerated running processes and collected their PIDs, names, and executable paths.T1059.003 · Windows Command ShellRokRAT executed received operating-system commands through cmd.exe.T1070.004 · File DeletionA RokRAT cleanup command deleted attack-related files and autorun traces; it also removed temporary file listings after upload.T1082 · System Information DiscoveryRokRAT collected operating-system and system-specific information, including SMBIOS-derived information, to identify the infected system.T1083 · File and Directory DiscoveryRokRAT enumerated drives, generated file listings, and recursively searched directories for files to collect.T1102.002 · Bidirectional CommunicationRokRAT used cloud-service REST APIs to retrieve commands and upload collected information through separate paths.T1113 · Screen CaptureRokRAT supported screen capture and uploaded captured data through its cloud C2 channel.T1140 · Deobfuscate/Decode Files or InformationThe shellcode used an XOR key to decode an encrypted payload before mapping it into memory.T1204.002 · Malicious FileThe attack induced recipients to execute a PDF-disguised PIF file inside the downloaded ISO.T1566.002 · Spearphishing LinkSpear-phishing emails presented a Dropbox download link as academic-event materials.