Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareRansomwareUsed by 2 actors

CHILLYCHINO

CHILLYCHINO is a Rust-based backdoor/implant associated with the North Korean threat group ScarCruft (APT37), specifically a subgroup tracked by S2W as ChinopuNK. Reporting states it was introduced in June 2025 and is the first known instance of APT37 using a Rust-based malware to target Windows systems. It is described as being adapted from a prior PowerShell version, and in later reporting as a new variant used in ScarCruft campaigns.

CHILLYCHINO was observed in phishing-driven intrusion chains targeting South Korean users. The lure involved emails themed as postal-code or street-address update notices, delivering a malicious LNK file embedded in a RAR or ZIP archive. Execution of the LNK dropped an AutoIt loader, which then fetched and executed additional payloads from an external server. In these campaigns, CHILLYCHINO was deployed alongside other malware including the NubSpy backdoor, LightPeek and FadeStealer stealers, TxPyLoader, and VCD ransomware.

The malware is part of a broader ScarCruft operational shift combining espionage tooling with ransomware deployment and abuse of real-time messaging infrastructure such as PubNub. High-confidence reporting links the campaign to ScarCruft based on overlapping tradecraft and malware clustering. Targeting described in the source material includes South Korean users, with ScarCruft historically targeting defectors, journalists, government entities, media organizations, academics, and defense- or North Korea-related victims. No specific CHILLYCHINO indicators of compromise are provided in the supplied content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT37

CHILLYCHINO : A Rust-based backdoor adapted from a prior PowerShell version.

via medium s2wblogmedium.com
ChinopuNK

CHILLYCHINO : A Rust-based backdoor adapted from a prior PowerShell version.

via medium s2wblogmedium.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

Upon execution, the LNK dropped an AutoIt loader, which then fetched and executed additional payloads including a stealer, ransomware, and backdoor from an external server.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.