OTX-69de00eccc0fa8439b871c56
info
📛 Threat Title
Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks
Description
APT37 conducted a sophisticated social engineering campaign utilizing Facebook accounts claiming locations in Pyongyang and Pyongsong, North Korea, to conduct reconnaissance and build trust with targets. After establishing relationships through Facebook Messenger, the threat actor migrated conversations to Telegram and employed pretexting tactics, claiming to share encrypted PDF documents containing military weapons information. Victims were persuaded to install a tampered Wondershare PDFelement installer that executed embedded shellcode for initial compromise. The attack chain delivered follow-on commands through a JPG-disguised payload hosted on a compromised Japanese real estate website. The malware abused Zoho WorkDrive OAuth2 APIs as C2 channels, exfiltrating screenshots, documents, system information, and audio files. The campaign employed multiple evasion techniques including code cave injection, process hollowing into legitimate dism.exe, XOR encryption layers, and fileless in-memory execution. Pulse contains 16 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (17)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
dism.exe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dism.exe
IOC database
- Type
- domain
- Value
dism.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat OTX-69de00eccc0fa8439b871c56
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dism.exe
hash_md5
28d0143718153bf04c1919a26bb70c2d
IOC database
- Type
- hash_md5
- Value
28d0143718153bf04c1919a26bb70c2d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
36be2cbb59cd1c3f745d5f80f9aee21c
IOC database
- Type
- hash_md5
- Value
36be2cbb59cd1c3f745d5f80f9aee21c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
c637b3e7d74c2d678663454d16311b15
IOC database
- Type
- hash_md5
- Value
c637b3e7d74c2d678663454d16311b15- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
c681fe3f42e82e9240afe97c23971cbc
IOC database
- Type
- hash_md5
- Value
c681fe3f42e82e9240afe97c23971cbc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
d44a22d2c969988a65c7d927e22364c8
IOC database
- Type
- hash_md5
- Value
d44a22d2c969988a65c7d927e22364c8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://japanroom.com/board/data/1288247428101.jpg
UrlVoid 2 / 35
IOC database
- Type
- url
- Value
http://japanroom.com/board/data/1288247428101.jpg- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
japanroom.com
1 feed
IOC database
- Type
- domain
- Value
japanroom.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
085128b4e96633c82beb2101f5c525e4
IOC database
- Type
- hash_md5
- Value
085128b4e96633c82beb2101f5c525e4- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
441603f740667fd5b4365b880b55a6cb6991cd96
IOC database
- Type
- hash_sha1
- Value
441603f740667fd5b4365b880b55a6cb6991cd96- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
6625f25a82a9739476402a759a514a59f822f5d8
IOC database
- Type
- hash_sha1
- Value
6625f25a82a9739476402a759a514a59f822f5d8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
d0f8b7885e65a2d0714f91f7275d100bca25a886
IOC database
- Type
- hash_sha1
- Value
d0f8b7885e65a2d0714f91f7275d100bca25a886- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
3ecb8632582982f5ea4cef6b32ac468bd43c61896b5de57416c8100f8ab90102
IOC database
- Type
- hash_sha256
- Value
3ecb8632582982f5ea4cef6b32ac468bd43c61896b5de57416c8100f8ab90102- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
8448b5ff7fac8b65dd9e5056a8a4b3e4230b7b602f46e24f1667821a64a90e6e
IOC database
- Type
- hash_sha256
- Value
8448b5ff7fac8b65dd9e5056a8a4b3e4230b7b602f46e24f1667821a64a90e6e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
d5a3321b215d2b141de7ebe24398cf43320a2016e4f20d079ddf7015ceb069a8
IOC database
- Type
- hash_sha256
- Value
d5a3321b215d2b141de7ebe24398cf43320a2016e4f20d079ddf7015ceb069a8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
dad0ca56b3fe2aeb1f7908765f279db5fc33392caf4849c573a5d63bf7e15604
IOC database
- Type
- hash_sha256
- Value
dad0ca56b3fe2aeb1f7908765f279db5fc33392caf4849c573a5d63bf7e15604- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
4137911f14563fdf7500159ee7a386d9c54bbdae
IOC database
- Type
- hash_sha1
- Value
4137911f14563fdf7500159ee7a386d9c54bbdae- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
-
OTX pulse
AlienVaulkt OTX
APT37 conducted a sophisticated social engineering campaign utilizing Facebook accounts claiming locations in Pyongyang and Pyongsong, North Korea, to conduct reconnaissance and build trust with targets. After establishing relationships through Facebook Messenger, the threat actor migrated conversations to Telegram and employed pretexting tactics, claiming to share encrypted PDF documents containing military weapons information. Victims were persuaded to install a tampered Wondershare PDFelement
- reference AlienVaulkt OTX
Remediations (8)
-
web:cybersecuritynews.com
A North Korean state-sponsored threat group known as APT37 has launched a new targeted intrusion campaign using social media platforms, encrypted messaging apps, and a carefully tampered software installer to compromise victims. The attack is notable for how convincingly it mimics everyday digital interactions, making it much harder for targets to recognize the threat before real damage is ...
-
web:malwaretips.com
APT37's Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks Pretexting by APT37 was identified. After Facebook contact, they sent an encrypted PDF via messenger and lured targets to install a viewer.
-
web:otx.alienvault.com
Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks
-
web:securitricks.com
Check the new attack report here : Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks - social engineering, north korea, rokrat, process hollowing, shellcode injection, apt37, 2026-04-14, facebook reconnaissance , installer tampering , pretexting
-
web:ti-mindmap-hub.com
APT37 orchestrated a sophisticated, multi-stage intrusion campaign by leveraging Facebook - based social engineering to build trust, tricking targets into installing a tampered PDF viewer that executed shellcode, and then covertly delivering follow-on payloads and exfiltrating data via legitimate cloud services and image-disguised network traffic ...
-
web:www.enigma-global.com
Genians Security Center conducted an in-depth analysis of a targeted intrusion campaign carried out by the APT37 threat actor through a social networking platform. The analysis showed that the threat actor used two Facebook accounts with their location set to Pyongyang and Pyongsong, North Korea
-
web:www.genians.co.kr
APT37의 프리텍스팅 기반 표적 침투: 페이스북 정찰과 소프트웨어 변조 공격 분석 APT37's Pretexting-Based Targeted Intrusion : Analysis of Facebook Reconnaissance and Software Tampering Attacks 🌐 View in English
-
web:www.genians.co.kr
This threat intelligence report provides a systematic analysis of the attacker's tactics, techniques, and procedures (TTPs), focusing on key technical artifacts such as Facebook - based target reconnaissance , shellcode execution through a tampered installer package, concealed C2 communication channels, and the delivery mechanism of an image ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.