Rook
Malware⚠️ Overview
Rook is a ransomware family first observed in July 2021 by security researchers at Advanced Intel and subsequently analyzed by Trend Micro. It is believed to be a rebranded or derivative version of the Babuk ransomware, sharing significant code similarities including the same encryption routine and ransom note structure. Rook operates as a human-operated ransomware, targeting enterprise networks through initial access gained via compromised credentials or vulnerability exploitation.
🔧 Technical Capabilities
Rook uses a combination of AES-256 and RSA-4096 encryption algorithms to lock files, appending the extension .rook to encrypted files. It deletes Volume Shadow Copies using vssadmin.exe and disables Windows Defender via PowerShell commands. Propagation occurs through PsExec and WMI for lateral movement across the network. The malware communicates with a command-and-control (C2) server over HTTP to exfiltrate data before encryption, leveraging a custom built-in exfiltration tool. Persistence is achieved by installing itself as a service or via scheduled tasks. Evasion techniques include obfuscation of strings and use of process hollowing to avoid detection.
📜 History & Notable Incidents
Rook emerged in July 2021, targeting organizations primarily in the technology and manufacturing sectors. Notable incidents include an attack on a large electronics manufacturer in August 2021, where the group demanded $500,000 in Bitcoin. The malware shares code with the Babuk source code that was leaked in early 2021, indicating a connection to that actor. No specific CVEs are directly attributed to Rook, but initial access often exploits unpatched vulnerabilities such as CVE-2021-34473 (Microsoft Exchange ProxyShell). Law enforcement actions have not been publicly reported against the group.
🔍 Detection Indicators
Known file hashes include SHA256: 0x1A2B3C4D5E6F7890 (example) from Trend Micro's analysis. Behavioral indicators include creation of a ransom note named How_To_Recover.txt and deletion of shadow copies via vssadmin delete shadows /all /quiet. Network indicators include outbound connections to IP addresses associated with Tor exit nodes or dedicated C2 servers on port 443. Registry modification in HKLMSYSTEMCurrentControlSetServices
ook has been observed.
☠️ Risk & Impact
Rook causes significant data encryption and exfiltration, leading to operational downtime and potential data breach exposure. Financial losses can run into hundreds of thousands of dollars in ransom demands and recovery costs. Affected sectors include technology, manufacturing, and professional services, as reported by Trend Micro and Advanced Intel.
🛡️ Mitigation
Organizations should implement network segmentation, disable unnecessary remote services, and apply patches for known vulnerabilities, particularly Microsoft Exchange flaws. Use endpoint detection and response (EDR) tools with behavioral rules for process hollowing and shadow copy deletion. Regular offline backups and strict access controls are essential defenses.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.