Chinopu NK

2025-08-07 • S2WScarCruft’s New Language: Whispering in PubNub, C…

S2W's Threat Analysis and Intelligence Center tracks ChinopuNK as an internally designated subgroup of the North Korean state-sponsored ScarCruft group, using the internal label "puNK" for partially unidentified North Korean threat actors; ChinopuNK had previously been linked to distribution of the Chinotto malware. In a campaign identified through August 2025, ChinopuNK used a malicious LNK file inside a RAR archive disguised as a South Korean postal-code update notice to deploy an AutoIt loader that fetched further payloads, including the NubSpy backdoor communicating over the PubNub messaging service, the PowerShell-based LightPeek stealer, the TxPyLoader Python loader, the previously documented FadeStealer exfiltration tool, VCD ransomware, and a Rust-based backdoor called CHILLYCHINO adapted from an earlier PowerShell version. The use of ransomware marked a notable departure from ScarCruft's historically espionage-focused operations, suggesting a possible shift toward financially motivated or disruptive objectives alongside continued reliance on real-time messaging platforms for command and control and ongoing efforts to port tooling to new programming languages for detection evasion.

Related Actors

Related Reports in This Cluster

Top Authors

View Chinopu NK reports only

View Chinopu NK reports only