APT37 Shifts to Facebook Social Engineering to Deliver RokRAT Malware

APT37 is not changing its malware but is innovating how it delivers RokRAT by exploiting Facebook’s social trust. The group uses friend requests and Messenger conversations to lure targets into installing a trojanized version of Wondershare PDFelement, which acts as a PDF viewer but executes embedded shellcode to deploy RokRAT. This bypasses traditional email- and browser-focused defenses by abusing social-media relationships as the attack vector. The campaign uses Facebook accounts set to North Korean locations created in November 2025 to screen and engage targets with pretexts about encrypted military documents. The trojanized PDFelement installer triggers RokRAT, which communicates through compromised legitimate websites and hides payloads as JPG images to evade detection. This delivery method leverages social engineering and software tampering rather than new malware variants. This shift means any user reachable via Facebook or Messenger, especially those with public-facing profiles or defense-related contacts, is at risk of targeted espionage. The persistence of RokRAT combined with evolving delivery tactics requires defenders to focus on detecting suspicious Messenger-originated social engineering and trojanized PDF viewers rather than relying solely on patching or email defenses.

Part of the PlainSec briefing for 2026-04-14

Sources