The Friend Request from Pyongyang: How APT37 Hijacks Facebook to Deploy RokRAT
ID: cf545b4c-f357-5541-b05c-44e3a59f1aaa
STIX ID: report--cf545b4c-f357-5541-b05c-44e3a59f1aaa
Feed Name: securityonline.info
Genians Security Center reports that APT37 has shifted to social-media initial access—using Facebook and Telegram social engineering—to deliver a tampered Wondershare PDFelement installer containing embedded shellcode (via PE patching). The attack then retrieves an encrypted second-stage payload masquerading as an image from a compromised legitimate website, executes it in memory (never written to disk), and deploys a RokRAT variant that leverages Zoho WorkDrive OAuth2 for stealthy C2; the report emphasizes behavioral EDR, threat hunting, and correlation-based detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
