logo

APT37 Leverages Malicious LNK Files and Dropbox for C2 Infrastructure

ID: 365c7afc-292a-545e-bd63-e29e962d63de

STIX ID: report--365c7afc-292a-545e-bd63-e29e962d63de

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

APT37 conducted a targeted spear-phishing campaign (Operation:ToyBox Story) using Dropbox-hosted ZIP archives containing malicious LNK files that trigger fileless PowerShell/batch loaders to deploy RoKRAT. The campaign leveraged trusted cloud services and VPNs to hide C2, executed in-memory shellcode, and used multi-layer encryption to exfiltrate sensitive system data and screenshots; the report includes MD5 hashes, C2 IPs, and multiple email addresses as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.