A reported spear-phishing campaign borrowed real event details, then used an ISO container and process injection to move RokRAT onto Windows systems.