APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks

2026-04-12 Genians

https://www.genians.co.kr/en/blog/threat_intelligence/pretexting

Thumbnail for APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks

APT37 used Facebook accounts presenting locations in Pyongyang and Pyongsong to identify targets, build trust through friend requests and Messenger conversations, and move victims toward Telegram delivery. The lure claimed encrypted military-weapons PDF documents required a dedicated viewer, leading targets to run a tampered Wondershare PDFelement installer named to resemble a security-related PDF viewer. The modified installer changed its entry point to execute shellcode from a code cave, then returned to normal installation behavior while enabling initial compromise. Follow-on activity abused the Seoul branch site of a Japanese real-estate information service as C2 infrastructure and delivered a JPG-disguised payload, highlighting a chain built around legitimate software tampering, legitimate infrastructure abuse, and extension masquerading.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dad0ca56b3fe2aeb1f7908765f279db… 2026-04-12 2026-04-12
HASH d5a3321b215d2b141de7ebe24398cf4… 2026-04-12 2026-04-12
HASH 3ecb8632582982f5ea4cef6b32ac468… 2026-04-12 2026-04-12
HASH 8448b5ff7fac8b65dd9e5056a8a4b3e… 2026-04-12 2026-04-12
HASH c637b3e7d74c2d678663454d16311b15 2026-04-12 2026-04-12
HASH 085128b4e96633c82beb2101f5c525e4 2026-04-12 2026-04-12
EMAIL [email protected] 2026-04-12 2026-04-12
URL http://japanroom.com/board/DATA… 2026-04-12 2026-04-12
DOMAIN japanroom.com 2026-04-12 2026-04-12
IPv4 222.122.49.15 2026-04-12 2026-04-12
EMAIL [email protected] 2025-08-03 2026-04-12
IPv4 38.32.68.195 2025-02-25 2026-04-12

Related Actors

Related Reports

« Back