Chinopu NK
2025-08-07 • S2W • ScarCruft’s New Language: Whispering in PubNub, C…
S2W's Threat Analysis and Intelligence Center tracks ChinopuNK as an internally designated subgroup of the North Korean state-sponsored ScarCruft group, using the internal label "puNK" for partially unidentified North Korean threat actors; ChinopuNK had previously been linked to distribution of the Chinotto malware. In a campaign identified through August 2025, ChinopuNK used a malicious LNK file inside a RAR archive disguised as a South Korean postal-code update notice to deploy an AutoIt loader that fetched further payloads, including the NubSpy backdoor communicating over the PubNub messaging service, the PowerShell-based LightPeek stealer, the TxPyLoader Python loader, the previously documented FadeStealer exfiltration tool, VCD ransomware, and a Rust-based backdoor called CHILLYCHINO adapted from an earlier PowerShell version. The use of ransomware marked a notable departure from ScarCruft's historically espionage-focused operations, suggesting a possible shift toward financially motivated or disruptive objectives alongside continued reliance on real-time messaging platforms for command and control and ongoing efforts to port tooling to new programming languages for detection evasion.
-
26
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster