NubSpy
NubSpy is a backdoor used in campaigns attributed to ChinopuNK, a subgroup of the North Korean state-sponsored threat group ScarCruft (APT37). It uses the legitimate PubNub real-time messaging platform for command-and-control communication, allowing malicious traffic to blend into normal network activity. Reported delivery in the referenced campaign involved phishing lures themed as postal code update notices, with a malicious LNK file embedded in a RAR archive; execution led to an AutoIt loader that fetched additional payloads, including NubSpy, from an external server. The campaign targeted South Korean users and organizations and was described as part of a broader multi-malware intrusion set that also included LightPeek, FadeStealer, CHILLYCHINO, TxPyLoader, and VCD ransomware. High-confidence associations in the content link NubSpy to ScarCruft’s longstanding abuse of real-time messaging infrastructure such as PubNub, with researchers citing this tradecraft as supporting attribution. No specific file hashes, domains, or other concrete IOCs for NubSpy were provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that uses PubNub as its command-and-control channel.
Backdoor malware that uses the PubNub cloud service for command-and-control, deployed via phishing campaigns by the Scarcruft (APT37) subgroup ChinopuNK.
NubSpy is a backdoor malware used by North Korean threat actors, notable for using PubNub as its C2 channel, enabling persistent remote access and control.
Backdoor malware that enables remote control of infected systems and uses PubNub for covert command and control communication.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.