North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
ID: 81de446a-147e-5088-86ff-e94618905ea1
STIX ID: report--81de446a-147e-5088-86ff-e94618905ea1
Feed Name: The Hacker News
The report attributes a multi-stage social engineering campaign to North Korean APT37 (ScarCruft) that used Facebook friend requests and Messenger-to-Telegram contact to convince targets to install a trojanized Wondershare PDFelement; the tampered installer runs embedded shellcode to contact a compromised site (japanroom.com), download a JPG-based second-stage payload and ultimately deploy RokRAT which uses Zoho WorkDrive for C2 to perform remote execution, reconnaissance and data capture while evading security tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
