Threat reportAPTTL-2026-1526

APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer

highACTIVE

APT37 Pretexting Campaign (TL-2026-1526), also tracked as Operation Pretexting, is a high-severity advanced persistent threat campaign, first published 2026-07-19. It is attributed to APT37 (North Korea) with high confidence, affects Wondershare PDFelement, maps to 29 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1APT37
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-1526

Threat ID
TL-2026-1526
Also known as
Operation Pretexting, Facebook-to-Telegram RokRAT Campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
APT37
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
government administration, defense, military, academic research
Target regions
south korea, japan, North America
Detection rules
9
Indicators of compromise
22

Malware and tooling in APT37 Pretexting Campaign

Malware and tooling: RokRAT

How APT37 Pretexting Campaign works

North Korea-linked APT37 (ScarCruft) built trust on Facebook using two fake personas, moved targets to Telegram, and delivered a trojanized Wondershare PDFelement installer disguised as a viewer for 'encrypted military documents'. The installer process-hollows dism.exe to launch RokRAT, which fetches a steganographic JPG second-stage from a compromised Japanese real-estate website and exfiltrates data via hardcoded Zoho WorkDrive OAuth2 tokens.

Genians Security Center documented a targeted intrusion attributed to APT37 (aka ScarCruft, Reaper, Group123, Ricochet Chollima, InkySquid, Red Eyes, APT-C-28, ATK4, Moldy Pisces) in which the threat actor established rapport with victims via two Facebook accounts, 'richardmichael0828' and 'johnsonsophia0414', both created on 2025-11-10 and geolocated to Pyongyang and Pyongsong, North Korea. After friend requests and Messenger conversations built around military and technical-cooperation pretexts, the actor moved the conversation to Telegram and delivered an encrypted archive 'm.zip' containing a tampered Wondershare PDFelement installer (Wondershare_PDFelement_Installer(PDF_Security).exe), several decoy PDF documents with military-themed titles rendered in the North Korean 'Chollima' typeface, and a Korean-language instructions file ('설명서_(instructions)_.txt') containing North Korean dialect terms such as '콤퓨터' (computer) and '프로그람' (program). The archive password was shared separately over Telegram.

The tampered installer retains the legitimate Wondershare application's functionality but lacks the vendor's digital signature and carries roughly 2 KB of shellcode injected into an unused code cave at offset 0x0015A0E0. On execution, the shellcode dynamically constructs the path to %windir%\System32\dism.exe using 4-byte MOV instructions, creates the process suspended (CREATE_SUSPENDED), allocates PAGE_EXECUTE_READWRITE memory via VirtualAllocEx, XOR-decrypts (key 0x6D) an embedded payload, writes it via WriteProcessMemory, and launches it with CreateRemoteThread — classic process hollowing (T1055.012) with retry logic (up to 5 attempts at 0.1s intervals) before returning control to the legitimate installer flow to preserve appearances.

The injected payload retrieves a second stage disguised as a JPEG image at http://japanroom[.]com/board/DATA/1288247428101.jpg. japanroom[.]com is the Seoul branch website of a legitimate Japanese real-estate information service that has been compromised to host attacker infrastructure, allowing the C2 traffic to blend into normal web activity and evade domain-reputation blacklisting. The delivered file has its MZ/PE header signatures stripped but preserves internal PE structure; a single-byte XOR (key derived from the first byte of the file) decrypts it, which is validated against the 0x55 0x8B (PUSH EBP / MOV EBP,ESP) function prologue, followed by a second 4-byte DWORD XOR layer (key 0x86F68586) across an 851,968-byte payload, ultimately reconstructing the RokRAT backdoor entirely in memory (fileless execution).

RokRAT performs system reconnaissance (computer name, username, Windows version, IP/geolocation, SMBIOS identifiers, running process list), screen capture (GetDC/GetSystemMetrics/CreateCompatibleBitmap/BitBlt, JPEG-encoded), arbitrary command execution via 'cmd.exe /c', and document/media collection targeting .DOC, .XLS, .PPT, .PDF, .HWP, .TXT, .M4A, and .AMR files. It performs defense evasion by enumerating running processes for Qihoo 360 (360Tray.exe) and carries 21 distinct User-Agent strings to blend into web traffic. All collected data is encrypted with AES-256-CBC prior to exfiltration. Debug/tracking strings recovered from the sample include 'JinHyok', '#FBI#TOOLKIT#GIDRA@TEAM', and '@-IV-FBI-SERVER2', consistent with prior North Korea-nexus tooling.

Command-and-control and exfiltration abuse the Zoho WorkDrive OAuth2 API using two sets of hardcoded client_id/refresh_token/client_secret credentials, disguising C2 and exfiltration traffic as legitimate cloud-storage business traffic. This technique mirrors the 'Ruby Jumper' campaign documented by Zscaler ThreatLabz in February 2026, in which RokRAT abused Zoho WorkDrive for command retrieval and data exfiltration, and matches historical APT37 Zoho account abuse (scott.snyder@zoho.com in 2017; leon91729@zoho.com identified H2 2025, registered under alias 'kingtiger1970').

Genians assessed high code similarity between the RokRAT sample recovered here and a RokRAT variant analyzed in December 2025 (shared XOR decryption chains, reconnaissance/command/screenshot functionality), and linked the steganographic JPG-masquerade technique to prior Genians reporting on RokRAT shellcode/steganographic delivery (image files carrying executable payloads after valid headers, e.g. a sample disguised as mpr.dll with an embedded MYIMAGEFILE resource). No CVEs are involved — the entire initial-access chain relies on social engineering (pretexting) rather than software exploitation. No BeaconBeagle correlation was found for the japanroom[.]com C2 domain or the associated IP addresses at the time of this analysis.

MITRE ATT&CK techniques used in TL-2026-1526

Collection

T1005 Data from Local System; T1113 Screen Capture; T1119 Automated Collection

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type; T1055.012 Process Hollowing; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567.002 Exfiltration to Cloud Storage

Execution

T1059.003 Windows Command Shell; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography

Persistence

T1543 Create or Modify System Process

lateral-movement

T1550.001 Application Access Token

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service

Resource Development

T1584.004 Server; T1585.001 Social Media Accounts

Reconnaissance

T1589.001 Credentials

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in APT37 Pretexting Campaign

  • Wondershare — PDFelement
    Vulnerable versions: tampered/trojanized installer distributed outside official channels
    Fixed in: N/A - not a vendor vulnerability; only obtain PDFelement from official Wondershare channels
  • Microsoft — Windows (dism.exe / DISM utility)
    Vulnerable versions: all supported Windows versions shipping dism.exe, abused as a process-hollowing target
    Fixed in: N/A - technique abuse, not a vendor vulnerability

Remediation for APT37 Pretexting Campaign

Immediate actions

  • Block the C2 domain japanroom[.]com and associated URI path /board/DATA/ at web proxy/DNS layer
  • Block IPs 38.32.68[.]195 and 222.122.49[.]15 at perimeter firewall
  • Revoke and rotate any Zoho WorkDrive OAuth2 client_id/refresh_token/client_secret pairs found hardcoded or referenced in endpoint traffic
  • Hunt for the identified MD5 hashes across endpoints and quarantine matching binaries
  • Alert users who received Facebook friend requests from 'richardmichael0828' or 'johnsonsophia0414' or similar Pyongyang/Pyongsong-geolocated accounts

Workarounds

  • Restrict dism.exe execution via application control policies where not required for legitimate deployment operations
  • Require digital-signature verification for third-party installer execution via Windows AppLocker/WDAC

Longer-term hardening

  • Deploy EDR with behavioral detection for process hollowing into dism.exe and other native Windows utilities
  • Implement application allow-listing to prevent execution of unsigned/tampered installers masquerading as trusted vendor software
  • Monitor and restrict outbound traffic to cloud storage OAuth endpoints (Zoho, Dropbox, pCloud, Yandex) for anomalous automated access patterns
  • Deploy user awareness training on social-media pretexting and cross-platform (Facebook-to-Telegram) handoff social engineering
  • Verify code-signing status of all software installers before user execution is permitted

Weaknesses (CWE) in APT37 Pretexting Campaign

CWE-506

Timeline of APT37 Pretexting Campaign

  • Genians publishes 'Operation ToyBox Story', detailing APT37 spear-phishing impersonating a Korean think tank with cloud-based C2 evasion, part of the same tooling lineage referenced in this campaign's analysis
  • Genians publishes 'RoKRAT Shellcode and Steganographic Threats' analysis, documenting RokRAT payloads concealed inside image files (e.g., a sample disguised as mpr.dll with an embedded MYIMAGEFILE resource) — the technique lineage behind this campaign's JPG-masqueraded second stage
  • Zoho account 'leon91729@zoho.com' (registered under alias 'kingtiger1970') identified in H2 2025 as part of APT37's Zoho WorkDrive OAuth2 C2/exfiltration abuse pattern
  • APT37 creates two Facebook social-engineering accounts, 'richardmichael0828' and 'johnsonsophia0414', geolocated to Pyongyang and Pyongsong, North Korea
  • Zscaler ThreatLabz identifies the 'Ruby Jumper' APT37/ScarCruft campaign (also tracked as Ruby Sleet, Velvet Chollima), later documented as abusing Zoho WorkDrive, OneDrive, Google Drive, and pCloud for C2 via a five-tool toolkit (RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE) and air-gap bridging over removable media
  • Operation Artemis (HWP-based DLL side-loading) documented by Genians, part of the same APT37 tooling lineage
  • Genians analyzes a RokRAT variant sharing high code similarity (XOR decryption chains, reconnaissance/command/screenshot functionality) with the sample later linked to this campaign
  • Zscaler ThreatLabz publishes the full 'Ruby Jumper' campaign report detailing RokRAT's abuse of Zoho WorkDrive OAuth2 for command retrieval and data exfiltration
  • Genians Security Center first observes the Facebook pretexting-to-Telegram delivery chain and the tampered PDFelement installer in the wild
  • The Hacker News and other outlets report on the campaign, amplifying defender awareness
  • Genians publishes 'APT37's Pretexting-Based Targeted Intrusion' report detailing the full attack chain, IOCs, and attribution

Sources cited for APT37 Pretexting Campaign

Detection coverage for TL-2026-1526

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1526 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats