Threat reportAPTTL-2026-1526
APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer
APT37 Pretexting Campaign (TL-2026-1526), also tracked as Operation Pretexting, is a high-severity advanced persistent threat campaign, first published 2026-07-19. It is attributed to APT37 (North Korea) with high confidence, affects Wondershare PDFelement, maps to 29 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1APT37
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-1526
- Threat ID
- TL-2026-1526
- Also known as
- Operation Pretexting, Facebook-to-Telegram RokRAT Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- APT37
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government administration, defense, military, academic research
- Target regions
- south korea, japan, North America
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in APT37 Pretexting Campaign
Malware and tooling: RokRAT
How APT37 Pretexting Campaign works
North Korea-linked APT37 (ScarCruft) built trust on Facebook using two fake personas, moved targets to Telegram, and delivered a trojanized Wondershare PDFelement installer disguised as a viewer for 'encrypted military documents'. The installer process-hollows dism.exe to launch RokRAT, which fetches a steganographic JPG second-stage from a compromised Japanese real-estate website and exfiltrates data via hardcoded Zoho WorkDrive OAuth2 tokens.
Genians Security Center documented a targeted intrusion attributed to APT37 (aka ScarCruft, Reaper, Group123, Ricochet Chollima, InkySquid, Red Eyes, APT-C-28, ATK4, Moldy Pisces) in which the threat actor established rapport with victims via two Facebook accounts, 'richardmichael0828' and 'johnsonsophia0414', both created on 2025-11-10 and geolocated to Pyongyang and Pyongsong, North Korea. After friend requests and Messenger conversations built around military and technical-cooperation pretexts, the actor moved the conversation to Telegram and delivered an encrypted archive 'm.zip' containing a tampered Wondershare PDFelement installer (Wondershare_PDFelement_Installer(PDF_Security).exe), several decoy PDF documents with military-themed titles rendered in the North Korean 'Chollima' typeface, and a Korean-language instructions file ('설명서_(instructions)_.txt') containing North Korean dialect terms such as '콤퓨터' (computer) and '프로그람' (program). The archive password was shared separately over Telegram.
The tampered installer retains the legitimate Wondershare application's functionality but lacks the vendor's digital signature and carries roughly 2 KB of shellcode injected into an unused code cave at offset 0x0015A0E0. On execution, the shellcode dynamically constructs the path to %windir%\System32\dism.exe using 4-byte MOV instructions, creates the process suspended (CREATE_SUSPENDED), allocates PAGE_EXECUTE_READWRITE memory via VirtualAllocEx, XOR-decrypts (key 0x6D) an embedded payload, writes it via WriteProcessMemory, and launches it with CreateRemoteThread — classic process hollowing (T1055.012) with retry logic (up to 5 attempts at 0.1s intervals) before returning control to the legitimate installer flow to preserve appearances.
The injected payload retrieves a second stage disguised as a JPEG image at http://japanroom[.]com/board/DATA/1288247428101.jpg. japanroom[.]com is the Seoul branch website of a legitimate Japanese real-estate information service that has been compromised to host attacker infrastructure, allowing the C2 traffic to blend into normal web activity and evade domain-reputation blacklisting. The delivered file has its MZ/PE header signatures stripped but preserves internal PE structure; a single-byte XOR (key derived from the first byte of the file) decrypts it, which is validated against the 0x55 0x8B (PUSH EBP / MOV EBP,ESP) function prologue, followed by a second 4-byte DWORD XOR layer (key 0x86F68586) across an 851,968-byte payload, ultimately reconstructing the RokRAT backdoor entirely in memory (fileless execution).
RokRAT performs system reconnaissance (computer name, username, Windows version, IP/geolocation, SMBIOS identifiers, running process list), screen capture (GetDC/GetSystemMetrics/CreateCompatibleBitmap/BitBlt, JPEG-encoded), arbitrary command execution via 'cmd.exe /c', and document/media collection targeting .DOC, .XLS, .PPT, .PDF, .HWP, .TXT, .M4A, and .AMR files. It performs defense evasion by enumerating running processes for Qihoo 360 (360Tray.exe) and carries 21 distinct User-Agent strings to blend into web traffic. All collected data is encrypted with AES-256-CBC prior to exfiltration. Debug/tracking strings recovered from the sample include 'JinHyok', '#FBI#TOOLKIT#GIDRA@TEAM', and '@-IV-FBI-SERVER2', consistent with prior North Korea-nexus tooling.
Command-and-control and exfiltration abuse the Zoho WorkDrive OAuth2 API using two sets of hardcoded client_id/refresh_token/client_secret credentials, disguising C2 and exfiltration traffic as legitimate cloud-storage business traffic. This technique mirrors the 'Ruby Jumper' campaign documented by Zscaler ThreatLabz in February 2026, in which RokRAT abused Zoho WorkDrive for command retrieval and data exfiltration, and matches historical APT37 Zoho account abuse (scott.snyder@zoho.com in 2017; leon91729@zoho.com identified H2 2025, registered under alias 'kingtiger1970').
Genians assessed high code similarity between the RokRAT sample recovered here and a RokRAT variant analyzed in December 2025 (shared XOR decryption chains, reconnaissance/command/screenshot functionality), and linked the steganographic JPG-masquerade technique to prior Genians reporting on RokRAT shellcode/steganographic delivery (image files carrying executable payloads after valid headers, e.g. a sample disguised as mpr.dll with an embedded MYIMAGEFILE resource). No CVEs are involved — the entire initial-access chain relies on social engineering (pretexting) rather than software exploitation. No BeaconBeagle correlation was found for the japanroom[.]com C2 domain or the associated IP addresses at the time of this analysis.
MITRE ATT&CK techniques used in TL-2026-1526
Collection
T1005 Data from Local System; T1113 Screen Capture; T1119 Automated Collection
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage
Execution
T1059.003 Windows Command Shell; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography
Persistence
T1543 Create or Modify System Process
lateral-movement
T1550.001 Application Access Token
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service
Resource Development
T1584.004 Server; T1585.001 Social Media Accounts
Reconnaissance
defense-impairment
Affected products and versions in APT37 Pretexting Campaign
- Wondershare — PDFelement
Vulnerable versions: tampered/trojanized installer distributed outside official channels
Fixed in: N/A - not a vendor vulnerability; only obtain PDFelement from official Wondershare channels - Microsoft — Windows (dism.exe / DISM utility)
Vulnerable versions: all supported Windows versions shipping dism.exe, abused as a process-hollowing target
Fixed in: N/A - technique abuse, not a vendor vulnerability
Remediation for APT37 Pretexting Campaign
Immediate actions
- Block the C2 domain japanroom[.]com and associated URI path /board/DATA/ at web proxy/DNS layer
- Block IPs 38.32.68[.]195 and 222.122.49[.]15 at perimeter firewall
- Revoke and rotate any Zoho WorkDrive OAuth2 client_id/refresh_token/client_secret pairs found hardcoded or referenced in endpoint traffic
- Hunt for the identified MD5 hashes across endpoints and quarantine matching binaries
- Alert users who received Facebook friend requests from 'richardmichael0828' or 'johnsonsophia0414' or similar Pyongyang/Pyongsong-geolocated accounts
Workarounds
- Restrict dism.exe execution via application control policies where not required for legitimate deployment operations
- Require digital-signature verification for third-party installer execution via Windows AppLocker/WDAC
Longer-term hardening
- Deploy EDR with behavioral detection for process hollowing into dism.exe and other native Windows utilities
- Implement application allow-listing to prevent execution of unsigned/tampered installers masquerading as trusted vendor software
- Monitor and restrict outbound traffic to cloud storage OAuth endpoints (Zoho, Dropbox, pCloud, Yandex) for anomalous automated access patterns
- Deploy user awareness training on social-media pretexting and cross-platform (Facebook-to-Telegram) handoff social engineering
- Verify code-signing status of all software installers before user execution is permitted
Weaknesses (CWE) in APT37 Pretexting Campaign
Timeline of APT37 Pretexting Campaign
- Genians publishes 'Operation ToyBox Story', detailing APT37 spear-phishing impersonating a Korean think tank with cloud-based C2 evasion, part of the same tooling lineage referenced in this campaign's analysis
- Genians publishes 'RoKRAT Shellcode and Steganographic Threats' analysis, documenting RokRAT payloads concealed inside image files (e.g., a sample disguised as mpr.dll with an embedded MYIMAGEFILE resource) — the technique lineage behind this campaign's JPG-masqueraded second stage
- Zoho account 'leon91729@zoho.com' (registered under alias 'kingtiger1970') identified in H2 2025 as part of APT37's Zoho WorkDrive OAuth2 C2/exfiltration abuse pattern
- APT37 creates two Facebook social-engineering accounts, 'richardmichael0828' and 'johnsonsophia0414', geolocated to Pyongyang and Pyongsong, North Korea
- Zscaler ThreatLabz identifies the 'Ruby Jumper' APT37/ScarCruft campaign (also tracked as Ruby Sleet, Velvet Chollima), later documented as abusing Zoho WorkDrive, OneDrive, Google Drive, and pCloud for C2 via a five-tool toolkit (RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE) and air-gap bridging over removable media
- Operation Artemis (HWP-based DLL side-loading) documented by Genians, part of the same APT37 tooling lineage
- Genians analyzes a RokRAT variant sharing high code similarity (XOR decryption chains, reconnaissance/command/screenshot functionality) with the sample later linked to this campaign
- Zscaler ThreatLabz publishes the full 'Ruby Jumper' campaign report detailing RokRAT's abuse of Zoho WorkDrive OAuth2 for command retrieval and data exfiltration
- Genians Security Center first observes the Facebook pretexting-to-Telegram delivery chain and the tampered PDFelement installer in the wild
- The Hacker News and other outlets report on the campaign, amplifying defender awareness
- Genians publishes 'APT37's Pretexting-Based Targeted Intrusion' report detailing the full attack chain, IOCs, and attribution
Sources cited for APT37 Pretexting Campaign
- APT37's Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks
- RoKRAT Shellcode and Steganographic Threats: Analysis and EDR Response Strategies
- Operation ToyBox Story
- Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks
- North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
- North Korean APT37 Hackers Leverages Zoho WorkDrive to Infect Air-Gapped Systems
- ScarCruft Exploits Zoho WorkDrive and USB Malware to Compromise Air-Gapped Government and Defense Networks
- APT37, InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, G0067
- APT37 (Threat Actor) Profile
- APT37 Threat Actor Profile - Tactics, Techniques, and Updates
Detection coverage for TL-2026-1526
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1526 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.