A reported spear-phishing campaign borrowed real event details, then used an ISO container and process injection to move RokRAT onto Windows systems.
A targeted phishing campaign used academic event PDFs and cloud links to deliver RokRAT, showing how trusted document workflows can be turned into an access path.
North Korea’s notorious hackers weaponize social media trust and legitimate software to unleash the stealthy RokRAT trojan.