Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareUsed by 2 actorsExploits 1 CVE

FadeStealer

FadeStealer is a ScarCruft-linked malware family used for data exfiltration. The provided content describes it as a previously documented stealer associated with the North Korean state-sponsored APT group ScarCruft, including activity attributed by S2W TALON to ChinopuNK, a ScarCruft subgroup. In the reported campaign targeting South Korean users, the infection chain used a malicious LNK file embedded in a RAR archive themed as a postal-code update notice. Execution of the LNK dropped an AutoIt loader, which retrieved additional payloads from an external server, including FadeStealer alongside other malware such as NubSpy, LightPeek, VCD Ransomware, and CHILLYCHINO. FadeStealer is explicitly described as supporting data exfiltration and as collecting keylogging data, screenshots, audio, device information, and file data. The campaign context ties it to spearphishing-style delivery and Windows host compromise. High-confidence associations in the content link FadeStealer to APT37/ScarCruft operations and targeting of South Korean users.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2021-40444Microsoft MSHTML Remote Code Execution Vulnerability

Windows Office Product Dropped Cab or Inf File ... Spearphishing Attachments, Microsoft MSHTML Remote Code Execution CVE-2021-40444, Compromised Windows Host, APT37 Rustonotto and FadeStealer

via splunk researchresearch.splunk.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT37

FadeStealer : A previously documented ScarCruft-linked malware designed for data exfiltration.

via medium s2wblogmedium.com
TA-RedAnt

“FadeStealer: … keylogging, screenshots, audio, device, and file data”

via ahnlab asec blogasec.ahnlab.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence2

Annotations ID Technique Tactic T1566.001 Spearphishing Attachment Initial Access

Execution

2 techniques
T1059.001PowerShellEvidence1

PowerShell 4104 Hunting ... T1059.001 ... Malicious PowerShell

T1204.001Malicious LinkEvidence1

Annotations ID Technique Tactic T1204.001 Malicious Link Execution

Command and Control

1 technique
T1105Ingress Tool TransferEvidence2

Upon execution, the LNK dropped an AutoIt loader, which then fetched and executed additional payloads including a stealer, ransomware, and backdoor from an external server.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

FadeStealer : A previously documented ScarCruft-linked malware designed for data exfiltration.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.