We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Trojan:O97M/RokRat
Aliases: No associated aliases
Summary
ROKRAT is a remote access trojan (RAT) that takes advantages of a malicious Hangul Word Processor (HWP) document. The document contains an embedded Encapsulated PostScript (EPS) object, spread through phishing emails or exploit kits, which exploits a known vulnerability (designated as CVE-2013-0808). The use of a Korean language word processor suggests that attacks associated with this threat target South Korean users.
Users should have Microsoft Defender updated to help mitigate the threat. Use Defender for regular system scans and removal of detected possible threats.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.