APT37 Leverages Malicious LNK Files and Dropbox for C2 Infrastructure
ID: 365c7afc-292a-545e-bd63-e29e962d63de
STIX ID: report--365c7afc-292a-545e-bd63-e29e962d63de
Feed Name: Cyber Press
Threat Score
APT37 conducted a targeted spear-phishing campaign (Operation:ToyBox Story) using Dropbox-hosted ZIP archives containing malicious LNK files that trigger fileless PowerShell/batch loaders to deploy RoKRAT. The campaign leveraged trusted cloud services and VPNs to hide C2, executed in-memory shellcode, and used multi-layer encryption to exfiltrate sensitive system data and screenshots; the report includes MD5 hashes, C2 IPs, and multiple email addresses as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
