216.73.217.22

Windows Targeted with Rust Backdoor and Python Loader

· Published 08/09/2025 14:41 · Modified 08/09/2025 15:34

Export JSON

Essential information

Published
08/09/2025 14:41
Modified
08/09/2025 15:34
Tags
2025-09-08 chinotto code injection data exfiltration fadestealer rust backdoor rustonotto spear-phishing surveillance
Related entities
1 observables, 1 intrusion sets (apt), 12 techniques (mitre), 3 malware, 1 others

Description

APT37, a North Korean threat actor, has been observed using new tactics and tools in recent campaigns. They have deployed a Rust-based backdoor named , alongside the existing PowerShell-based malware and . The group utilizes Windows shortcut files and help files as initial infection vectors. Their sophisticated attack chain includes spear phishing, Compiled HTML Help file delivery, and Transactional NTFS for stealthy . The threat actor employs a single command-and-control server to orchestrate all components of their malware arsenal. , a tool, is capable of logging keystrokes, capturing screenshots and audio, tracking devices, and exfiltrating data through password-protected RAR archives.

External references