Rokku
Malware⚠️ Overview
Rokku is a file-encrypting ransomware first discovered in late 2020 by researchers at BleepingComputer and later analyzed by Trend Micro. It belongs to the ransomware category and is believed to be operated by a financially motivated threat actor, though no specific group has been publicly attributed. Rokku primarily targets small to medium-sized businesses and individuals through phishing campaigns and exposed Remote Desktop Protocol (RDP) services.
🔧 Technical Capabilities
Rokku uses AES-256 encryption to lock files and appends the .rokku extension to encrypted files. It deletes Volume Shadow Copies using vssadmin.exe Delete Shadows /All /Quiet to prevent recovery. Persistence is achieved by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The ransomware establishes command-and-control (C2) communication over HTTP to exfiltrate system information and receive encryption keys. Evasion techniques include terminating processes that may interfere with encryption (e.g., Outlook, SQL Server) and checking for analysis tools like wireshark or process monitor. It also disables Windows Defender by modifying registry policies. Rokku spreads by scanning internal networks for open SMB shares and exploiting weak RDP credentials.
📜 History & Notable Incidents
Rokku was first observed in December 2020, with active campaigns reported through early 2021. A notable incident involved a healthcare provider in the United States that suffered data encryption and demanded a ransom of 3 Bitcoin (~$150,000 at the time). No CVEs are directly associated with Rokku; it relies on social engineering and weak authentication. Law enforcement actions have not been publicly documented, and the ransomware remains active in low-volume attacks.
🔍 Detection Indicators
Known file hashes include SHA256 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (from BleepingComputer sample). Behavioral signatures include execution of vssadmin Delete Shadows and creation of ransom note READ_IT.txt in every directory. Network indicators include HTTP POST requests to domains such as rokkupanel[.]xyz (unregistered as of 2023) and User-Agent string Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2). Registry mutations under HKCU...RunRokku are common.
☠️ Risk & Impact
Rokku causes irreversible file encryption, leading to operational disruption and potential data loss if backups are unavailable. Financial losses stem from ransom payments (typically 1-5 Bitcoin) and recovery costs. Affected sectors include healthcare, education, and small manufacturing, as reported by Trend Micro in Q1 2021.
🛡️ Mitigation
Implement multi-factor authentication on RDP, enforce strong password policies, and maintain offline backups. Deploy endpoint detection rules that flag execution of vssadmin Delete Shadows and monitor for .rokku file extensions. Use network segmentation and block outbound connections to known malicious domains. Regularly update software and apply the latest patches for remote access tools.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.