logo

APT37 Uses Facebook, Telegram, and Trojanized Installer In New Intrusion Campaign

ID: dc1e212c-1094-57bf-99c9-a67e5bf7f007

STIX ID: report--dc1e212c-1094-57bf-99c9-a67e5bf7f007

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-13

Date Updated: 2026-04-19

Author: Varshini

...
...

APT37 ran a targeted social‑engineering campaign using Facebook personas and Telegram to distribute a trojanized Wondershare PDFelement installer that deploys a RokRAT‑like backdoor. The malware captures screenshots, executes commands, enumerates hosts, and exfiltrates documents and audio via Zoho WorkDrive using hardcoded OAuth2 credentials and AES‑256‑CBC encryption, while employing evasion techniques and infrastructure linked to North Korea.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.