VCD Ransomware

#VCD • 2025-08

S2W TALON attributed a South Korea-focused postal-code update lure campaign to ChinopuNK, a ScarCruft subgroup, with malicious LNK files in RAR archives dropping an AutoIt loader and retrieving follow-on payloads from external infrastructure. The payload set included VCD ransomware alongside NubSpy, LightPeek, TxPyLoader, FadeStealer, and the Rust-based CHILLYCHINO backdoor, showing ScarCruft expanding from espionage tradecraft into ransomware deployment and modernized malware development.

Related Actors

Scarcruft

Kaspersky

ScarCruft is a codename introduced by Kaspersky for an APT group first identified through Operation Daybreak, a March 2016 spear-phishing campaign that used a previously unknown Adobe Flash Player exploit to compromise more than two dozen high-profile victims in Russia, Nepal, South Korea, China, India, Kuwait, and Romania; the group was also linked to an earlier campaign, Operation Erebus, which used watering-hole attacks with a separate Flash exploit. Kaspersky assessed ScarCruft's tradecraft and tooling as professional and well above average for a group that had, at the time, managed to remain largely undetected. In subsequent Kaspersky reporting, ScarCruft, also referred to elsewhere as APT37 or Temp.Reaper, continued targeting North Korean defectors, journalists covering North Korea, and government organizations tied to the Korean Peninsula. One investigation found the group had compromised a victim's social media and email accounts to approach and spear-phish the victim's associates, deploying PowerShell, Windows, and Android malware that shared a common command-and-control scheme, with related activity traced back to at least mid-2020.

Operation Daybreak
First seen: 2016-06 • Last seen: 2026-07

Related Reports

« Back