Operation Capsule Vault: Analysis of a RokRAT Attack Chain Using EMBED_PAYLOAD_v2

· Original article ↗

Summary

Genians analyzed a spear-phishing campaign that delivered RokRAT through a PDF-disguised PIF inside a Dropbox-hosted ISO. The multi-stage loader used shellcode and process injection; researchers assess APT37 was highly likely responsible.

Key points

  • Spear-phishing emails impersonated materials from a real academic event and targeted people in research, policy, and academic fields.
  • A Dropbox link delivered an ISO containing a PIF executable disguised as a PDF; the file displayed a decoy document while running malicious code.
  • The EMBED_PAYLOAD_v2 loader extracted embedded shellcode, decrypted a payload in memory, and injected it into explorer.exe.
  • The injected RokRAT variant supports cloud C2 through pCloud, Dropbox, and Yandex and can collect system information, screenshots, drive listings, and files, as well as execute commands.
  • Genians assesses APT37 was highly likely responsible, citing code and infrastructure overlaps with previously analyzed RokRAT activity, while noting code similarity alone cannot establish attribution.
  • Defenders should correlate phishing, ISO and PIF execution, process injection, memory activity, and cloud C2 behavior; the report also provides IOC IP addresses.

Article Details

Attack Vectors
  • Spear-phishing emails sent on 2026-06-22 impersonated the distribution of materials from an actual academic event and linked to a malicious ISO image hosted on Dropbox.
  • The ISO contained a PIF executable disguised with a PDF-like filename and icon. Execution displayed a legitimate-looking PDF while extracting an embedded shellcode payload.
  • The loader decoded the payload in memory and injected a RokRAT variant into explorer.exe.
  • RokRAT used cloud-service APIs for command retrieval and data upload, and supported remote command execution, file collection, screen capture, and execution of additional payloads.
Defensive Notes
  • Correlate spear-phishing delivery, ISO downloads, and execution of PDF-disguised PIF files, including double-extension filenames.
  • Monitor PIF-initiated memory allocation, writes into explorer.exe, remote-thread creation, and subsequent cloud-service connections.
  • Use EDR behavior and network telemetry together to trace the attack chain rather than relying only on file signatures or isolated network events.

Indicators of compromise

TypeIndicatorContext
EMAILjohnson8903013@gmail[.]comListed by Genians among indicators associated with the threat actor's spear-phishing activity and attack infrastructure.
IPV4160[.]238[.]37[.]100Listed as an attack-related IP indicator; identified as a Nord VPN exit node.
IPV4160[.]238[.]37[.]95Listed as an attack-related IP indicator; identified as a Nord VPN exit node.
IPV45[.]180[.]208[.]57Listed as an IP indicator used in the threat actor's spear-phishing activity or attack infrastructure.
IPV45[.]180[.]208[.]60Listed as an IP indicator used in the threat actor's spear-phishing activity or attack infrastructure.
IPV489[.]147[.]101[.]197Listed as an attack-related IP indicator; identified as a Nord VPN exit node.
IPV489[.]187[.]161[.]220Listed as an attack-related IP indicator; identified as an Astrill VPN exit node.
MD5e5c9bb3938f2a24e755ee39073fc3acaMalicious-file hash published in the report's IoC section.

MITRE ATT&CK

T1027.009 · Embedded PayloadsThe PIF loader stored a decoy PDF and a shellcode binary in an EMBED_PAYLOAD_v2 embedded payload table.T1036.007 · Double File ExtensionThe malicious executable used a PDF-like filename ending in .pdf.pif to conceal its executable extension.T1041 · Exfiltration Over C2 ChannelRokRAT uploaded collected files, system information, and screen captures through its cloud C2 communication.T1055 · Process InjectionThe loader wrote the restored payload into explorer.exe and started it through a remote thread.T1057 · Process DiscoveryRokRAT enumerated running processes and collected their PIDs, names, and executable paths.T1059.003 · Windows Command ShellRokRAT executed received operating-system commands through cmd.exe.T1070.004 · File DeletionA RokRAT cleanup command deleted attack-related files and autorun traces; it also removed temporary file listings after upload.T1082 · System Information DiscoveryRokRAT collected operating-system and system-specific information, including SMBIOS-derived information, to identify the infected system.T1083 · File and Directory DiscoveryRokRAT enumerated drives, generated file listings, and recursively searched directories for files to collect.T1102.002 · Bidirectional CommunicationRokRAT used cloud-service REST APIs to retrieve commands and upload collected information through separate paths.T1113 · Screen CaptureRokRAT supported screen capture and uploaded captured data through its cloud C2 channel.T1140 · Deobfuscate/Decode Files or InformationThe shellcode used an XOR key to decode an encrypted payload before mapping it into memory.T1204.002 · Malicious FileThe attack induced recipients to execute a PDF-disguised PIF file inside the downloaded ISO.T1566.002 · Spearphishing LinkSpear-phishing emails presented a Dropbox download link as academic-event materials.

Threat Actors

Malware

Vendors

Products

Countries

Industries

Related Articles