VCD is a ransomware deployed by the ChinopuNK subgroup of Scarcruft (APT37), a North Korean threat actor, as part of a multiphase campaign targeting South Korean entities. The campaign, active since at least July 2025, uses phishing emails disguised as postal code update notices as the initial infection vector. VCD ransomware appends a .vcd extension to encrypted files and drops ransom notes in both English and Korean, indicating targeting of South Korean victims. The ransomware binaries are hardcoded with specific file paths to encrypt, demonstrating a high degree of customization and likely leveraging intelligence gathered by infostealers deployed earlier in the attack chain. The campaign is notable for blending espionage and financially motivated cybercrime, reflecting a broader DPRK trend. VCD is deployed alongside other malware such as NubSpy, FadeStealer, LightPeek, and a Rust-rewritten ChillyChino backdoor, with advanced evasion techniques like transacted hollowing and Rust-based payloads. Scarcruft's use of ransomware is rare and marks a strategic shift toward multipurpose, multiphase attacks that enable both intelligence gathering and financial or disruptive objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware used by North Korean APTs, appends .vcd extension, drops ransom notes in English and Korean, and is tailored to specific targets based on prior reconnaissance.
Ransomware that encrypts files and demands a ransom, marking a shift by ScarCruft from espionage to financially motivated attacks.
Ransomware that encrypts files and appends the .vcd extension, dropping ransom notes in English and Korean. Used by ScarCruft in recent attacks, indicating a possible shift to financially motivated or extortion-driven tactics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.