s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-69de00eccc0fa8439b871c56 info

📛 Threat Title

Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks

Category: APT37 Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

APT37 conducted a sophisticated social engineering campaign utilizing Facebook accounts claiming locations in Pyongyang and Pyongsong, North Korea, to conduct reconnaissance and build trust with targets. After establishing relationships through Facebook Messenger, the threat actor migrated conversations to Telegram and employed pretexting tactics, claiming to share encrypted PDF documents containing military weapons information. Victims were persuaded to install a tampered Wondershare PDFelement installer that executed embedded shellcode for initial compromise. The attack chain delivered follow-on commands through a JPG-disguised payload hosted on a compromised Japanese real estate website. The malware abused Zoho WorkDrive OAuth2 APIs as C2 channels, exfiltrating screenshots, documents, system information, and audio files. The campaign employed multiple evasion techniques including code cave injection, process hollowing into legitimate dism.exe, XOR encryption layers, and fileless in-memory execution. Pulse contains 16 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (17)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain dism.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dism.exe

IOC database

Type
domain
Value
dism.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat OTX-69de00eccc0fa8439b871c56

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dism.exe

hash_md5 28d0143718153bf04c1919a26bb70c2d

IOC database

Type
hash_md5
Value
28d0143718153bf04c1919a26bb70c2d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 36be2cbb59cd1c3f745d5f80f9aee21c

IOC database

Type
hash_md5
Value
36be2cbb59cd1c3f745d5f80f9aee21c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 c637b3e7d74c2d678663454d16311b15

IOC database

Type
hash_md5
Value
c637b3e7d74c2d678663454d16311b15
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 c681fe3f42e82e9240afe97c23971cbc

IOC database

Type
hash_md5
Value
c681fe3f42e82e9240afe97c23971cbc
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 d44a22d2c969988a65c7d927e22364c8

IOC database

Type
hash_md5
Value
d44a22d2c969988a65c7d927e22364c8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://japanroom.com/board/data/1288247428101.jpg UrlVoid 2 / 35

IOC database

Type
url
Value
http://japanroom.com/board/data/1288247428101.jpg
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain japanroom.com 1 feed

IOC database

Type
domain
Value
japanroom.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 085128b4e96633c82beb2101f5c525e4

IOC database

Type
hash_md5
Value
085128b4e96633c82beb2101f5c525e4
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 441603f740667fd5b4365b880b55a6cb6991cd96

IOC database

Type
hash_sha1
Value
441603f740667fd5b4365b880b55a6cb6991cd96
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 6625f25a82a9739476402a759a514a59f822f5d8

IOC database

Type
hash_sha1
Value
6625f25a82a9739476402a759a514a59f822f5d8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 d0f8b7885e65a2d0714f91f7275d100bca25a886

IOC database

Type
hash_sha1
Value
d0f8b7885e65a2d0714f91f7275d100bca25a886
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 3ecb8632582982f5ea4cef6b32ac468bd43c61896b5de57416c8100f8ab90102

IOC database

Type
hash_sha256
Value
3ecb8632582982f5ea4cef6b32ac468bd43c61896b5de57416c8100f8ab90102
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 8448b5ff7fac8b65dd9e5056a8a4b3e4230b7b602f46e24f1667821a64a90e6e

IOC database

Type
hash_sha256
Value
8448b5ff7fac8b65dd9e5056a8a4b3e4230b7b602f46e24f1667821a64a90e6e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 d5a3321b215d2b141de7ebe24398cf43320a2016e4f20d079ddf7015ceb069a8

IOC database

Type
hash_sha256
Value
d5a3321b215d2b141de7ebe24398cf43320a2016e4f20d079ddf7015ceb069a8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 dad0ca56b3fe2aeb1f7908765f279db5fc33392caf4849c573a5d63bf7e15604

IOC database

Type
hash_sha256
Value
dad0ca56b3fe2aeb1f7908765f279db5fc33392caf4849c573a5d63bf7e15604
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 4137911f14563fdf7500159ee7a386d9c54bbdae

IOC database

Type
hash_sha1
Value
4137911f14563fdf7500159ee7a386d9c54bbdae
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • OTX pulse AlienVaulkt OTX

    APT37 conducted a sophisticated social engineering campaign utilizing Facebook accounts claiming locations in Pyongyang and Pyongsong, North Korea, to conduct reconnaissance and build trust with targets. After establishing relationships through Facebook Messenger, the threat actor migrated conversations to Telegram and employed pretexting tactics, claiming to share encrypted PDF documents containing military weapons information. Victims were persuaded to install a tampered Wondershare PDFelement

  • reference AlienVaulkt OTX

Remediations (8)

  • web:cybersecuritynews.com

    A North Korean state-sponsored threat group known as APT37 has launched a new targeted intrusion campaign using social media platforms, encrypted messaging apps, and a carefully tampered software installer to compromise victims. The attack is notable for how convincingly it mimics everyday digital interactions, making it much harder for targets to recognize the threat before real damage is ...

  • web:malwaretips.com

    APT37's Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks Pretexting by APT37 was identified. After Facebook contact, they sent an encrypted PDF via messenger and lured targets to install a viewer.

  • web:otx.alienvault.com

    Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks

  • web:securitricks.com

    Check the new attack report here : Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks - social engineering, north korea, rokrat, process hollowing, shellcode injection, apt37, 2026-04-14, facebook reconnaissance , installer tampering , pretexting

  • web:ti-mindmap-hub.com

    APT37 orchestrated a sophisticated, multi-stage intrusion campaign by leveraging Facebook - based social engineering to build trust, tricking targets into installing a tampered PDF viewer that executed shellcode, and then covertly delivering follow-on payloads and exfiltrating data via legitimate cloud services and image-disguised network traffic ...

  • web:www.enigma-global.com

    Genians Security Center conducted an in-depth analysis of a targeted intrusion campaign carried out by the APT37 threat actor through a social networking platform. The analysis showed that the threat actor used two Facebook accounts with their location set to Pyongyang and Pyongsong, North Korea

  • web:www.genians.co.kr

    APT37의 프리텍스팅 기반 표적 침투: 페이스북 정찰과 소프트웨어 변조 공격 분석 APT37's Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks 🌐 View in English

  • web:www.genians.co.kr

    This threat intelligence report provides a systematic analysis of the attacker's tactics, techniques, and procedures (TTPs), focusing on key technical artifacts such as Facebook - based target reconnaissance , shellcode execution through a tampered installer package, concealed C2 communication channels, and the delivery mechanism of an image ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.