Skip to content

APT37 Uses Facebook, Telegram, and Trojanzied Installer in New Targeted Cyberattack

Gbhackers •Mayura Kathir • April 13, 2026

APT37 is running a new targeted intrusion campaign that abuses , Telegram, and a tampered Wondershare PDFelement installer to gain stealthy access and exfiltrate sensitive data, likely from defense‑related targets. The operation shows a continued evolution of APT37’s social engineering and evasion tradecraft, and demands behavior‑based EDR capable of spotting process injection, abused cloud storage, […]

Extracted Entities