APT37 Uses Facebook, Telegram, and Trojanzied Installer in New Targeted Cyberattack
ID: c6dd3ee0-c428-58e6-ad48-dda41da33069
STIX ID: report--c6dd3ee0-c428-58e6-ad48-dda41da33069
Feed Name: GBHackers
APT37 conducted a targeted intrusion campaign using social-engineered Messenger/Telegram lures and a tampered Wondershare PDFelement installer that injects a multi-stage, XOR‑encrypted payload into a suspended dism.exe process, ultimately deploying a RokRAT-like backdoor that exfiltrates documents and screenshots via Zoho WorkDrive OAuth2-based C2. The operation is highly evasive (signed-binary abuse, fileless execution, image‑disguised payloads) and appears aimed at defense-related targets, warranting behavior-based EDR and monitoring for unsigned ‘update’ installers, suspicious dism.exe activity, and cloud-storage C2 patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
