#Chinotto
Malware/Tool
Chinotto is a PowerShell backdoor used by APT37, a North Korea-aligned threat actor, and has reportedly been active since 2019. Campaigns targeting South Korean financial and educational users hosted ZIP or RAR archives on public websites; those archives contained LNK or CHM files that ran malicious scripts and delivered Chinotto with an information stealer. Lures referenced credit cards, insurance bills, and other targeted themes, sometimes requiring a victim’s birth date to reveal content. Recent variants expanded from nine to twelve backdoor commands. APT37 has also operated Chinotto alongside Rustonotto and FadeStealer through a shared command-and-control server, while separate reporting describes two functionally similar Chinotto variants.
-
14
Tagged Reports
-
10
Unique Authors
-
1,380
Active Days