Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Wondershare Technology

Wondershare Technology Vendor Cyber Rating & Cyber Score

wondershare.com

Wondershare is a global tech company dedicated to providing creative solutions. As a leading tech startup, we offer a comprehensive portfolio of 60 different software products designed to simplify people's lives through innovative technology. Reaching across 150 countries, our commitment to simplicity and utility ensures user-friendly products that solve problems. At Wondershare, we believe in fostering a dynamic work environment with competitive salaries and excellent health benefits. Whether in marketing or creative roles, we are always on the lookout for innovators, creators, and leaders who are passionate about making a difference. Join us in our mission to delight and inspire through cutting-edge technology.


Wondershare Technology A.I CyberSecurity Scoring

Wondershare Technology
Company Information
Website:https://www.wondershare.com/
Employees number:643
Number of followers:21,591
NAICS:5112
Industry Type:Software Development
Homepage:wondershare.com
Wondershare Technology Risk Score (AI oriented)
Between 700 and 749
logo
Wondershare TechnologySoftware Development
Updated:
13/04/2026
740/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Wondershare Technology Global Score (TPRM)
xxxx
logo
Wondershare TechnologySoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Wondershare Technology
Wondershare TechnologyModerate
Current Score
740Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
741Before Incident
MAY 2026
741Before Incident
APRIL 2026
740Before Incident
MARCH 2026
740Before Incident
FEBRUARY 2026
740Before Incident
JANUARY 2026
739Before Incident
DECEMBER 2025
756Before Incident
Cyber Attack
01 Dec 2025Wondershare Technology
Wondershare and Zoho: APT37 Uses Facebook, Telegram, and Trojanzied Installer in New Targeted Cyberattack

APT37 Leverages Facebook, Telegram, and Tampered PDFelement Installer in Targeted Cyber Espionage Campaign

738After Incident
CRITICAL-18
ZOHWON1776076134
APT37 Leverages Facebook, Telegram, and Tampered PDFelement Installer in Targeted Cyber Espionage Campaign North Korea-linked threat group APT37 has launched a sophisticated cyber espionage campaign, abusing Facebook, Telegram, and a trojanized Wondershare PDFelement installer to infiltrate defense-related targets and exfiltrate sensitive data. The operation demonstrates the group’s evolving social engineering tactics and evasion techniques, bypassing traditional signature-based defenses. ### Attack Flow and Tactics The campaign begins with Facebook friend requests from two accounts impersonating individuals in Pyongyang and Pyeongtaek, North Korea, used to identify and vet targets. After establishing trust via one-on-one Messenger chats, the attackers shift conversations to Telegram, claiming to share encrypted military documents that require a "dedicated PDF viewer." Victims receive a password-protected ZIP file (e.g., m.zip) containing: - A fake PDF viewer executable (a modified Wondershare PDFelement installer) - Military-themed decoy PDFs - A Korean-language instructions file with North Korean spelling variations (e.g., "콤퓨터," "프로그람") The tampered installer, named Wondershare_PDFelement_Installer(PDF_Security).exe, mimics the legitimate version but lacks a valid Wondershare digital signature, serving as a key indicator of compromise (IoC). While the installer appears functional, its entry point is hijacked shellcode injected into a code cave redirects execution to malicious routines before resuming normal installation. ### Malicious Execution Chain 1. Shellcode Execution: The injected code resolves APIs via PEB-based hash routines, launches dism.exe in a suspended state, and injects a decrypted payload into its memory using VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. 2. C2 Communication: The shellcode retrieves a second-stage payload from a Japanese real estate website (disguised as a .jpg file). The response is XOR-encrypted, requiring two decryption passes first validating the payload with a standard x86 function prologue (55 8B), then reconstructing a PE image in memory with stripped MZ/PE headers. 3. RokRAT Backdoor Deployment: The final payload, resembling APT37’s RokRAT malware, conducts system reconnaissance, captures screenshots, and exfiltrates files (DOC, XLS, PDF, HWP, M4A, AMR). It abuses Zoho WorkDrive’s OAuth2 APIs for command-and-control (C2), blending with legitimate traffic using hardcoded client IDs, secrets, and refresh tokens. ### Attribution and Evasion Techniques The campaign aligns with APT37’s known tradecraft, including: - North Korean-language decoys and spelling patterns - Abuse of Zoho WorkDrive for C2 (previously observed in 2025) - Fileless execution and multi-stage XOR encryption - Process injection into signed binaries (dism.exe) to evade detection The group’s tactics tampered installers, cloud-based C2, and image-disguised payloads highlight the limitations of signature-based defenses, emphasizing the need for behavior-based EDR monitoring parent-child process chains, unsigned binaries, and anomalous dism.exe activity. The operation underscores APT37’s continued focus on defense and military targets, leveraging social engineering, legitimate platforms, and stealthy malware delivery to maintain persistence and exfiltrate sensitive data.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Espionage
IMPACT
Data Compromised: Sensitive military documents, system reconnaissance data, screenshots, files (DOC, XLS, PDF, HWP, M4A, AMR)Operational Impact: Data exfiltration, potential compromise of defense-related information
DATA BREACH
Military documentsSystem reconnaissance dataScreenshotsFiles (DOC, XLS, PDF, HWP, M4A, AMR)Sensitivity Of Data: HighDOCXLSPDFHWPM4AAMR
NOVEMBER 2025
756Before Incident
OCTOBER 2025
756Before Incident
SEPTEMBER 2025
756Before Incident
AUGUST 2025
756Before Incident
JULY 2025
756Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Wondershare Technology ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Wondershare Technology's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Wondershare Technology's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Wondershare Technology ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Wondershare Technology's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Wondershare Technology Cyber Scoring History | Rankiteo