Chinotto is a malware family/backdoor associated with North Korea-linked APT37/ScarCruft (also referenced in reporting on Reaper and the ChinopuNK sub-cluster). It is described across the provided content as a PowerShell-based backdoor used for espionage, surveillance, and data theft, and in some reporting as a highly customizable backdoor. Documented capabilities include command execution, file transfer, persistence via registry and scheduled tasks, exfiltration of system information, and broader information-stealing behavior. Reporting also links Chinotto-related activity to attacks on both Windows and Android systems.
Observed delivery methods include spear-phishing campaigns using archive files containing malicious CHM help files, LNK shortcuts, macro-enabled Word documents, HWP documents with embedded OLE objects, and a malicious Excel XLL add-in. Several chains use MSHTA to retrieve an HTA payload containing the Chinotto PowerShell backdoor. One described attack chain used ZIP archives with LNK or CHM files to drop CHILLYCHINO or Chinotto, which then contacted C2 to retrieve a next-stage payload responsible for launching FadeStealer. Another report identifies a final information-stealing payload named HncUpdate.exe/HqcUpdate.exe as Chinotto, noting it was created on 2020-11-11 01:20:09 UTC and was widely identified by the embedded PDB project name "Chinotto."
Victimology in the provided content includes journalists, human rights activists, North Korean defectors, South Korea-based North Korea-related professionals, and government-related targets, with campaigns often using themed social-engineering lures. Chinotto is repeatedly characterized as a long-used ScarCruft/APT37 malware family for espionage and data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In 2020, the APT37 group has conducted attacks by embedding OLE objects in HWP document files and using them to trigger CVE-2018-15982, a vulnerability in Adobe Flash Player. | The final payload identified at this stage, "HncUpdate.exe", is a malicious file with information-stealing capabilities that was created on 2020-11-11 01:20:09 (UTC). It is widely known by the project name "Chinotto", based on the PDB path embedded in the file.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload identified at this stage, "HncUpdate.exe", is a malicious file with information-stealing capabilities that was created on 2020-11-11 01:20:09 (UTC). It is widely known by the project name "Chinotto", based on the PDB path embedded in the file.
The campaign is attributed to ChinopuNK, a subgroup of ScarCruft tracked internally by S2W, which is known for distributing the Chinotto malware.
For years, the group relied on a malware family called Chinotto to carry out espionage and data theft.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the final information-stealing payload in the campaign.
An APT37-associated malware family used historically for espionage and data theft.
PowerShell backdoor supporting file transfer and command execution, with persistence via registry and scheduled tasks; delivered via LNK/CHM/HTA/PowerShell chains.
PowerShell-based backdoor used by APT37, often as a counterpart to CHILLYCHINO, to retrieve and launch additional payloads such as FadeStealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.