Chinotto is a cross-platform espionage backdoor family associated with the North Korean threat actor APT37, also known as ScarCruft or Reaper. It includes PowerShell implants, native Windows executables and DLLs, and Android spyware. Chinotto has been used for prolonged surveillance and data theft against North Korean defectors, human rights activists, journalists covering North Korea, and other individuals connected to the Korean Peninsula, particularly in South Korea.
Windows variants support remote command execution, file upload and download, directory archiving, bulk file collection, screenshot capture, malware updates, and configurable execution intervals. Persistence is established through Windows startup registry entries; PowerShell variants also support scheduled-task persistence. Some newer DLL variants perform predefined collection tasks rather than retrieving interactive commands, including frequent screenshot capture, keylogging with foreground-window context, and extension-filtered collection from user directories and removable storage. Android variants collect SMS messages, contacts, call logs, account and device information, photographs, and audio files, and can covertly record audio. Windows and Android variants share an HTTP-based command-and-control design, with compromised web servers used to receive stolen information and relay commands. Collected files can be archived and encrypted before exfiltration.
Chinotto is distributed through targeted spearphishing and multistage infection chains. Documented delivery mechanisms include malicious Word and Hangul Word Processor documents, Windows shortcut files, compressed HTML Help files, and malicious Excel add-ins, often packaged in archives with decoy documents. These chains frequently abuse MSHTA to retrieve an HTA containing a PowerShell implant. Chinotto can also retrieve or execute additional malware, serving as an entry point for further surveillance tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ASEC(AhnLab Security Emergengy response Center) 분석팀은 지난 1월 RedEyes 공격 그룹(also known as APT37, ScarCruft)이 한글 EPS(Encapulated PostScript) 취약점(CVE-2017-8291)을 통해 악성코드를 유포하는 정황을 확인하였다.
In 2020, the APT37 group has conducted attacks by embedding OLE objects in HWP document files and using them to trigger CVE-2018-15982, a vulnerability in Adobe Flash Player. | The final payload identified at this stage, "HncUpdate.exe", is a malicious file with information-stealing capabilities that was created on 2020-11-11 01:20:09 (UTC). It is widely known by the project name "Chinotto", based on the PDB path embedded in the file.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
또한, RedEyes 그룹은 PC 정보를 탈취하고 원격 제어를 수행하기 위해 파워쉘과 Chinotto 악성코드를 사용한다고 알려져 있다.
The campaign is attributed to ChinopuNK, a subgroup of ScarCruft tracked internally by S2W, which is known for distributing the Chinotto malware.
For years, the group relied on a malware family called Chinotto to carry out espionage and data theft.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
This registry key causes the HTML Application (HTA) file to get fetched and executed by the mshta.exe process every time the system is booted. The fetched ‘1.html’ is an HTML Application (.hta) file that contains Visual Basic Script (VBS), which eventually executes PowerShell commands.
a simple backdoor which communicates every 7 seconds to its C2 to receive a command to execute through cmd.exe /c [command]
This document contains a malicious macro and a payload for a multi-stage infection process. The first stage’s macro contains obfuscated strings and then spawns another macro as a second stage.
One of the characteristics of this malware is that it contains a lot of garbage code to impede analysis... It also restores functional strings such as C2 addresses and debugging messages to the stack at runtime.
The first stage macro contains obfuscated strings... If no Kaspersky security software is installed, the macro directly proceeds to decrypt the next stage’s payload.
In order to generate the identification value of the victim, the malware acquires both computer and user name and combines them in the format ‘%computer name%_%user name%’.
Granting these permissions allows the apps to collect sensitive information, including contacts, messages, call logs, device information and audio recordings.
Based on what we found from this victim, we can confirm that the malware operator collected screenshots and exfiltrated them between August 6, 2021 and September 8, 2021.
During our day to day hunting to protect our customers, we came across two Command and Control servers (C2s) of the North Korea-nexus intrusion set Reaper (aka APT37) with open directories...
The PowerShell script offers simple backdoor functionalities and continuously queries the C2 server with HTTP POST requests containing several parameters.
270 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ScarCruft/APT37-linked backdoor/spyware family used for surveillance, including monitoring individuals’ daily lives and Android targeting.
Named as the final information-stealing payload in the campaign.
An APT37-associated malware family used historically for espionage and data theft.
PowerShell backdoor supporting file transfer and command execution, with persistence via registry and scheduled tasks; delivered via LNK/CHM/HTA/PowerShell chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.