A Genians threat intelligence report detailed a targeted intrusion campaign attributed to APT37, the North Korea-linked group also tracked in connection with RokRat activity. The campaign reportedly relied on pretexting to engage victims, with operators conducting reconnaissance through Facebook before moving to compromise targets through software tampering techniques.
The reporting links the activity to the DPRK cyber threat ecosystem and highlights a blend of social engineering and supply-chain-style manipulation to gain access and advance intrusions. Public references to the report emphasized the campaign's use of staged victim profiling and trusted-software abuse, underscoring APT37's continued focus on tailored espionage operations.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Genians published a threat intelligence report analyzing an APT37 campaign that used pretexting, Facebook-based reconnaissance, and software tampering, and linked the activity to RokRat and DPRK-associated threat activity. The two Bluesky posts reference the same external report rather than separate incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.