Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jul 31, 2019 | Updated Dec 12, 2023

Trojan:O97M/RokRat

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

ROKRAT is a remote access trojan (RAT) that takes advantages of a malicious Hangul Word Processor (HWP) document. The document contains an embedded Encapsulated PostScript (EPS) object, spread through phishing emails or exploit kits, which exploits a known vulnerability (designated as CVE-2013-0808). The use of a Korean language word processor suggests that attacks associated with this threat target South Korean users.

Users should have Microsoft Defender updated to help mitigate the threat. Use Defender for regular system scans and removal of detected possible threats.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us