APT37 Uses Facebook, Telegram, and Trojanized Installer In New Intrusion Campaign
ID: dc1e212c-1094-57bf-99c9-a67e5bf7f007
STIX ID: report--dc1e212c-1094-57bf-99c9-a67e5bf7f007
Feed Name: Cyber Press
Threat Score
APT37 ran a targeted social‑engineering campaign using Facebook personas and Telegram to distribute a trojanized Wondershare PDFelement installer that deploys a RokRAT‑like backdoor. The malware captures screenshots, executes commands, enumerates hosts, and exfiltrates documents and audio via Zoho WorkDrive using hardcoded OAuth2 credentials and AES‑256‑CBC encryption, while employing evasion techniques and infrastructure linked to North Korea.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
