logo

North Korean cyber-espionage group ScarCruft adds ransomware in recent attack

ID: 93447700-fe65-5b7f-8a25-5c1f16c84c6b

STIX ID: report--93447700-fe65-5b7f-8a25-5c1f16c84c6b

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-08-08

Date Updated: 2026-05-01

...
...

ScarCruft (APT37), a North Korean state-linked actor, conducted a multi-malware campaign that for the first time included a newly observed ransomware (identified as VCD) alongside info-stealers (FadeStealer, LightPeek), a PubNub-based backdoor (NubSpy), and a new Chinotto variant (ChillyChino); researchers attribute the activity to the ChinopuNK subgroup and warn the ransomware deployment could indicate a shift toward financially motivated or disruptive extortion operations targeting entities in South Korea and other countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.