#Rustonotto

Malware/Tool

2025-09-08 • APT37: Rust Backdoor & Python Loader

Rustonotto, also called CHILLYCHINO, is a Rust-based backdoor used by APT37 from at least June 2025. It operated as part of a coordinated malware set that included the PowerShell-based Chinotto and the FadeStealer information stealer. The components shared a command-and-control server, allowing the actor to combine remote access and data theft within the same infrastructure. The campaign targeted South Korean individuals connected to North Korean affairs or human-rights work, aligning the backdoor's deployment with APT37's espionage objectives.

Tagged Reports

« Back