securityonline.info 9/10/2025, 1:46:37 AM · via preferred

APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer

APT37 Expands Arsenal with Rustonotto Backdoor, PowerShell Chinotto, and FadeStealer

ZSCALER ThreatLabz has uncovered North Korean-aligned threat actor APT37 (also known as ScarCruft, Ruby Sleet, or Velvet Chollima) expanding its arsenal with Rustonotto, a Rust-based backdoor first observed in June 2025, alongside Chinotto, a PowerShell-based tool active since 2019, and FadeStealer, a surveillance malware discovered in 2023.

The Rustonotto backdoor can execute Windows commands, exfiltrate results via Base64 encoding, and communicate with a central C2 server, with the trio—Rustonotto, Chinotto, and FadeStealer—operating under the same C2 infrastructure. Chinotto is delivered via Windows shortcut (LNK) or CHM files and supports persistence and remote control, while FadeStealer provides keylogging, screen capture, microphone recording, USB monitoring, and data exfiltration in encrypted RAR archives.

ThreatLabz notes that APT37 has been expanding its use of stealthy code injection methods, including TxF-based techniques and Process Doppelgänging combined with Python loaders, to inject payloads into legitimate Windows processes without leaving artefacts on disk. Most victims are reported to be in South Korea, with targets including individuals tied to North Korean interests or South Korean political and diplomatic circles. According to ThreatLabz, APT37 continues to blend social engineering with advanced tooling to exfiltrate data and conduct targeted surveillance.

View full article

Article by CyberSIXT