RAT
RokRAT
aka DOGCALL
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents.
RokRAT, also known as DOGCALL, is a Windows rat operated by APT37.
Background
This backdoor is typically delivered as an encoded binary that shellcode retrieves and decrypts after a weaponized document is exploited. DOGCALL can take screenshots, record keystrokes, dodge analysis through anti-virtual machine checks, and abuse cloud storage APIs including Cloud, Box, Dropbox, and Yandex.
Source: Malpedia (Fraunhofer FKIE).