APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks
2026-04-12 • Genians •
https://www.genians.co.kr/en/blog/threat_intelligence/pretexting
APT37 used Facebook accounts presenting locations in Pyongyang and Pyongsong to identify targets, build trust through friend requests and Messenger conversations, and move victims toward Telegram delivery. The lure claimed encrypted military-weapons PDF documents required a dedicated viewer, leading targets to run a tampered Wondershare PDFelement installer named to resemble a security-related PDF viewer. The modified installer changed its entry point to execute shellcode from a code cave, then returned to normal installation behavior while enabling initial compromise. Follow-on activity abused the Seoul branch site of a Japanese real-estate information service as C2 infrastructure and delivered a JPG-disguised payload, highlighting a chain built around legitimate software tampering, legitimate infrastructure abuse, and extension masquerading.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 28d0143718153bf04c1919a26bb70c2d | 2026-04-12 | 2026-04-12 |
| HASH | c681fe3f42e82e9240afe97c23971cbc | 2026-04-12 | 2026-04-12 |
| HASH | 36be2cbb59cd1c3f745d5f80f9aee21c | 2026-04-12 | 2026-04-12 |
| HASH | d44a22d2c969988a65c7d927e22364c8 | 2026-04-12 | 2026-04-12 |
| HASH | c637b3e7d74c2d678663454d16311b15 | 2026-04-12 | 2026-04-12 |
| HASH | 085128b4e96633c82beb2101f5c525e4 | 2026-04-12 | 2026-04-12 |
| [email protected] | 2026-04-12 | 2026-04-12 | |
| URL | http://japanroom.com/board/DATA… | 2026-04-12 | 2026-04-12 |
| DOMAIN | japanroom.com | 2026-04-12 | 2026-04-12 |
| [email protected] | 2025-08-03 | 2026-04-12 | |
| IPv4 | 38.32.68.195 | 2025-02-25 | 2026-04-12 |
| IPv4 | 222.122.49.15 | 2021-04-19 | 2026-04-12 |