TGTGInsighttelegram intelligenceLIVE / telegram public index
Post content
Post content
🚨 APT37 used Facebook to run a targeted malware campaign. Fake profiles built trust, moved chats to Telegram, then pushed a trojanized PDF app that installs RokRAT via a JPG payload, using compromised sites and Zoho WorkDrive for control. 🔗 Read → https://thehackernews.com/2026/04/north-koreas-apt37-uses-facebook-social.html