logo

North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware

ID: 81de446a-147e-5088-86ff-e94618905ea1

STIX ID: report--81de446a-147e-5088-86ff-e94618905ea1

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report attributes a multi-stage social engineering campaign to North Korean APT37 (ScarCruft) that used Facebook friend requests and Messenger-to-Telegram contact to convince targets to install a trojanized Wondershare PDFelement; the tampered installer runs embedded shellcode to contact a compromised site (japanroom.com), download a JPG-based second-stage payload and ultimately deploy RokRAT which uses Zoho WorkDrive for C2 to perform remote execution, reconnaissance and data capture while evading security tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.