North Korean Group ScarCruft Expands From Spying to Ransomware Attacks
ID: 12ba2d39-e7a6-5312-af1f-3b5f1f5aab3c
STIX ID: report--12ba2d39-e7a6-5312-af1f-3b5f1f5aab3c
Feed Name: HackRead
Threat Score
S2W researchers report that North Korean APT ScarCruft (ChinopuNK) executed a July phishing campaign in South Korea delivering a multi-stage payload — including a Rust backdoor using PubNub C2, various info-stealers, a ChillyChino variant, and a new VCD ransomware — indicating a shift from espionage-only operations toward blended financially motivated attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
