logo

APT37 Uses Facebook, Telegram, and Trojanzied Installer in New Targeted Cyberattack

ID: c6dd3ee0-c428-58e6-ad48-dda41da33069

STIX ID: report--c6dd3ee0-c428-58e6-ad48-dda41da33069

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-13

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

APT37 conducted a targeted intrusion campaign using social-engineered Messenger/Telegram lures and a tampered Wondershare PDFelement installer that injects a multi-stage, XOR‑encrypted payload into a suspended dism.exe process, ultimately deploying a RokRAT-like backdoor that exfiltrates documents and screenshots via Zoho WorkDrive OAuth2-based C2. The operation is highly evasive (signed-binary abuse, fileless execution, image‑disguised payloads) and appears aimed at defense-related targets, warranting behavior-based EDR and monitoring for unsigned ‘update’ installers, suspicious dism.exe activity, and cloud-storage C2 patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.