Skip to content

RAT

RokRAT

aka DOGCALL

It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents.

RokRAT, also known as DOGCALL, is a Windows rat operated by APT37.

Background

This backdoor is typically delivered as an encoded binary that shellcode retrieves and decrypts after a weaponized document is exploited. DOGCALL can take screenshots, record keystrokes, dodge analysis through anti-virtual machine checks, and abuse cloud storage APIs including Cloud, Box, Dropbox, and Yandex.


Source: Malpedia (Fraunhofer FKIE).