logo

The Friend Request from Pyongyang: How APT37 Hijacks Facebook to Deploy RokRAT

ID: cf545b4c-f357-5541-b05c-44e3a59f1aaa

STIX ID: report--cf545b4c-f357-5541-b05c-44e3a59f1aaa

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Genians Security Center reports that APT37 has shifted to social-media initial access—using Facebook and Telegram social engineering—to deliver a tampered Wondershare PDFelement installer containing embedded shellcode (via PE patching). The attack then retrieves an encrypted second-stage payload masquerading as an image from a compromised legitimate website, executes it in memory (never written to disk), and deploys a RokRAT variant that leverages Zoho WorkDrive OAuth2 for stealthy C2; the report emphasizes behavioral EDR, threat hunting, and correlation-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.