IntelNexus
Feed/North Korea's APT37 Uses Facebook Social
MEDIUMCYBERFREE

North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware

Provenance𝕏 Share14 viewsApr 13, 2026

The North Korean hacking group tracked as APT37 (aka ScarCruft) has been attributed to a fresh multi-stage, social engineering campaign in which threat actors approached targets on Facebook and added them as friends on the social media platform, turning the trust-building exercise into a delivery channel for a remote access trojan called RokRAT. "The threat actor used two Facebook Source: The Hacker News

North Korea's, KP

AI Credibility Assessment

43%
ANONYMOUS
Loading discussion…
click ↩ reply on any comment to fight back