# APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer

> North Korea-linked APT37 (ScarCruft) built trust on Facebook using two fake personas, moved targets to Telegram, and delivered a trojanized Wondershare PDFelement installer disguised as a viewer for 'encrypted military documents'. The installer process-hollows dism.exe to launch RokRAT, which fetches a steganographic JPG second-stage from a compromised Japanese real-estate website and exfiltrates data via hardcoded Zoho WorkDrive OAuth2 tokens.

- **Published:** 2026-07-19T00:00:00Z
- **Last reviewed:** 2026-07-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1526
- **ID:** TL-2026-1526
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** APT37 (North Korea)
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Genians Security Center documented a targeted intrusion attributed to APT37 (aka ScarCruft, Reaper, Group123, Ricochet Chollima, InkySquid, Red Eyes, APT-C-28, ATK4, Moldy Pisces) in which the threat actor established rapport with victims via two Facebook accounts, 'richardmichael0828' and 'johnsonsophia0414', both created on 2025-11-10 and geolocated to Pyongyang and Pyongsong, North Korea. After friend requests and Messenger conversations built around military and technical-cooperation pretexts, the actor moved the conversation to Telegram and delivered an encrypted archive 'm.zip' containing a tampered Wondershare PDFelement installer (Wondershare_PDFelement_Installer(PDF_Security).exe), several decoy PDF documents with military-themed titles rendered in the North Korean 'Chollima' typeface, and a Korean-language instructions file ('설명서_(instructions)_.txt') containing North Korean dialect terms such as '콤퓨터' (computer) and '프로그람' (program). The archive password was shared separately over Telegram.

The tampered installer retains the legitimate Wondershare application's functionality but lacks the vendor's digital signature and carries roughly 2 KB of shellcode injected into an unused code cave at offset 0x0015A0E0. On execution, the shellcode dynamically constructs the path to %windir%\System32\dism.exe using 4-byte MOV instructions, creates the process suspended (CREATE_SUSPENDED), allocates PAGE_EXECUTE_READWRITE memory via VirtualAllocEx, XOR-decrypts (key 0x6D) an embedded payload, writes it via WriteProcessMemory, and launches it with CreateRemoteThread — classic process hollowing (T1055.012) with retry logic (up to 5 attempts at 0.1s intervals) before returning control to the legitimate installer flow to preserve appearances.

The injected payload retrieves a second stage disguised as a JPEG image at http://japanroom[.]com/board/DATA/1288247428101.jpg. japanroom[.]com is the Seoul branch website of a legitimate Japanese real-estate information service that has been compromised to host attacker infrastructure, allowing the C2 traffic to blend into normal web activity and evade domain-reputation blacklisting. The delivered file has its MZ/PE header signatures stripped but preserves internal PE structure; a single-byte XOR (key derived from the first byte of the file) decrypts it, which is validated against the 0x55 0x8B (PUSH EBP / MOV EBP,ESP) function prologue, followed by a second 4-byte DWORD XOR layer (key 0x86F68586) across an 851,968-byte payload, ultimately reconstructing the RokRAT backdoor entirely in memory (fileless execution).

RokRAT performs system reconnaissance (computer name, username, Windows version, IP/geolocation, SMBIOS identifiers, running process list), screen capture (GetDC/GetSystemMetrics/CreateCompatibleBitmap/BitBlt, JPEG-encoded), arbitrary command execution via 'cmd.exe /c', and document/media collection targeting .DOC, .XLS, .PPT, .PDF, .HWP, .TXT, .M4A, and .AMR files. It performs defense evasion by enumerating running processes for Qihoo 360 (360Tray.exe) and carries 21 distinct User-Agent strings to blend into web traffic. All collected data is encrypted with AES-256-CBC prior to exfiltration. Debug/tracking strings recovered from the sample include 'JinHyok', '#FBI#TOOLKIT#GIDRA@TEAM', and '@-IV-FBI-SERVER2', consistent with prior North Korea-nexus tooling.

Command-and-control and exfiltration abuse the Zoho WorkDrive OAuth2 API using two sets of hardcoded client_id/refresh_token/client_secret credentials, disguising C2 and exfiltration traffic as legitimate cloud-storage business traffic. This technique mirrors the 'Ruby Jumper' campaign documented by Zscaler ThreatLabz in February 2026, in which RokRAT abused Zoho WorkDrive for command retrieval and data exfiltration, and matches historical APT37 Zoho account abuse (scott.snyder@zoho.com in 2017; leon91729@zoho.com identified H2 2025, registered under alias 'kingtiger1970').

Genians assessed high code similarity between the RokRAT sample recovered here and a RokRAT variant analyzed in December 2025 (shared XOR decryption chains, reconnaissance/command/screenshot functionality), and linked the steganographic JPG-masquerade technique to prior Genians reporting on RokRAT shellcode/steganographic delivery (image files carrying executable payloads after valid headers, e.g. a sample disguised as mpr.dll with an embedded MYIMAGEFILE resource). No CVEs are involved — the entire initial-access chain relies on social engineering (pretexting) rather than software exploitation. No BeaconBeagle correlation was found for the japanroom[.]com C2 domain or the associated IP addresses at the time of this analysis.

## MITRE ATT&CK

- T1589.001 Credentials
- T1585.001 Social Media Accounts
- T1584.004 Server
- T1566.003 Spearphishing via Service
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1059.003 Windows Command Shell
- T1543 Create or Modify System Process
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1055.012 Process Hollowing
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1057 Process Discovery
- T1518.001 Security Software Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1119 Automated Collection
- T1071.001 Web Protocols
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1573.001 Symmetric Cryptography
- T1567.002 Exfiltration to Cloud Storage
- T1041 Exfiltration Over C2 Channel
- T1550.001 Application Access Token

## Sources

- [APT37's Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks](https://www.genians.co.kr/en/blog/threat_intelligence/pretexting)
- [RoKRAT Shellcode and Steganographic Threats: Analysis and EDR Response Strategies](https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_shellcode_steganographic)
- [Operation ToyBox Story](https://www.genians.co.kr/en/blog/threat_intelligence/toybox-story)
- [Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks](https://www.genians.co.kr/en/blog/threat_intelligence/dll)
- [North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware](https://thehackernews.com/2026/04/north-koreas-apt37-uses-facebook-social.html)
- [North Korean APT37 Hackers Leverages Zoho WorkDrive to Infect Air-Gapped Systems](https://cybersecuritynews.com/north-korean-apt37-hackers-leverages-novel-malware/)
- [ScarCruft Exploits Zoho WorkDrive and USB Malware to Compromise Air-Gapped Government and Defense Networks](https://www.rescana.com/post/scarcruft-exploits-zoho-workdrive-and-usb-malware-to-compromise-air-gapped-government-and-defense-ne)
- [APT37, InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, Ricochet Chollima, G0067](https://attack.mitre.org/groups/G0067/)
- [APT37 (Threat Actor) Profile](https://malpedia.caad.fkie.fraunhofer.de/actor/apt37)
- [APT37 Threat Actor Profile - Tactics, Techniques, and Updates](https://www.huntress.com/threat-library/threat-actors/apt37)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1526
