Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
AI Analysis
Technical Summary
This threat involves a multi-stage spear-phishing attack that targets research, policy, and academic individuals by sending emails that appear to be from a real academic conference. The attack delivers a malicious ISO file containing a PIF executable disguised as a PDF document. The loader uses the EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which are extracted and executed in memory sequentially. The malware injects shellcode into the explorer.exe process to deploy a RokRAT variant. RokRAT communicates with cloud-based command-and-control infrastructure via pCloud, Dropbox, and Yandex Cloud services. The campaign demonstrates advanced social engineering and evasion techniques, including process injection and cloud-hosted C2 operations. Attribution analysis links the campaign to APT37 based on infrastructure overlap, code similarities, and operational patterns. Indicators of compromise include specific IP addresses and a file hash. There is no known CVE or patch available for this threat.
Potential Impact
The campaign enables remote attackers to execute malicious code on targeted systems through spear-phishing and multi-stage payload execution. RokRAT malware deployed via this attack can establish persistent access and communicate with cloud-based C2 servers, potentially leading to data exfiltration or further system compromise. The use of legitimate-looking documents and cloud services for command-and-control increases the difficulty of detection and mitigation.
Mitigation Recommendations
No official patch or remediation is currently available for this threat. Defenders should be aware of spear-phishing tactics involving academic conference-themed lures and malicious ISO attachments containing disguised executables. Monitoring for the identified indicators of compromise, including the listed IP addresses and file hash, may assist in detection. Network monitoring for unusual traffic to cloud services such as pCloud, Dropbox, and Yandex Cloud is recommended. User awareness training to recognize spear-phishing attempts is advised. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Indicators of Compromise
- ip: 89.187.161.220
- ip: 5.180.208.57
- ip: 5.180.208.60
- ip: 160.238.37.95
- ip: 89.147.101.197
- ip: 160.238.37.100
- hash: e5c9bb3938f2a24e755ee39073fc3aca
Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2
Description
A sophisticated spear-phishing campaign targeted individuals in research, policy, and academic fields through emails disguised as materials from an actual academic conference. The attack leveraged a cloud storage link delivering a malicious ISO file containing a PIF executable disguised as a PDF document. The multi-stage loader used EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which were sequentially extracted and executed in memory. Shellcode injection into explorer.exe ultimately deployed a RokRAT variant communicating with cloud-based C2 infrastructure via pCloud, Dropbox, and Yandex Cloud. The campaign demonstrated advanced social engineering by exploiting information from a real event, combined with sophisticated evasion techniques including process injection and cloud-based command-and-control operations. Attribution analysis linked the activity to APT37 based on infrastructure overlap, code similarities, and operational patterns.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a multi-stage spear-phishing attack that targets research, policy, and academic individuals by sending emails that appear to be from a real academic conference. The attack delivers a malicious ISO file containing a PIF executable disguised as a PDF document. The loader uses the EMBED_PAYLOAD_v2 structure to embed both legitimate documents and malicious payloads, which are extracted and executed in memory sequentially. The malware injects shellcode into the explorer.exe process to deploy a RokRAT variant. RokRAT communicates with cloud-based command-and-control infrastructure via pCloud, Dropbox, and Yandex Cloud services. The campaign demonstrates advanced social engineering and evasion techniques, including process injection and cloud-hosted C2 operations. Attribution analysis links the campaign to APT37 based on infrastructure overlap, code similarities, and operational patterns. Indicators of compromise include specific IP addresses and a file hash. There is no known CVE or patch available for this threat.
Potential Impact
The campaign enables remote attackers to execute malicious code on targeted systems through spear-phishing and multi-stage payload execution. RokRAT malware deployed via this attack can establish persistent access and communicate with cloud-based C2 servers, potentially leading to data exfiltration or further system compromise. The use of legitimate-looking documents and cloud services for command-and-control increases the difficulty of detection and mitigation.
Defensive Guidance
No official patch or remediation is currently available for this threat. Defenders should be aware of spear-phishing tactics involving academic conference-themed lures and malicious ISO attachments containing disguised executables. Monitoring for the identified indicators of compromise, including the listed IP addresses and file hash, may assist in detection. Network monitoring for unusual traffic to cloud services such as pCloud, Dropbox, and Yandex Cloud is recommended. User awareness training to recognize spear-phishing attempts is advised. Patch status is not yet confirmed — check vendor advisories and threat intelligence sources for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault?hs_amp=true"]
- Adversary
- APT37
- Pulse Id
- 6a5414fab18f9d7456d7eda8
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip89.187.161.220 | CC=JP ASN=AS60068 datacamp limited | |
ip5.180.208.57 | CC=US ASN=AS62240 clouvider limited | |
ip5.180.208.60 | CC=US ASN=AS62240 clouvider limited | |
ip160.238.37.95 | CC=PE ASN=ASNone | |
ip89.147.101.197 | CC=HU ASN=AS201237 on line system kft. | |
ip160.238.37.100 | CC=PE ASN=ASNone |
Hash
| Value | Description | Copy |
|---|---|---|
hashe5c9bb3938f2a24e755ee39073fc3aca | — |
Threat ID: 6a54bece68715ace43aa4058
Added to database: 07/13/2026, 10:32:46 UTC
Last enriched: 08/12/2026, 12:42:41 UTC
Last updated: 08/24/2026, 09:34:36 UTC
Views: 274
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.