logo

North Korean Group ScarCruft Expands From Spying to Ransomware Attacks

ID: 12ba2d39-e7a6-5312-af1f-3b5f1f5aab3c

STIX ID: report--12ba2d39-e7a6-5312-af1f-3b5f1f5aab3c

Feed Name: HackRead

Threat Score
85/100

Date Published: 2025-08-11

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

S2W researchers report that North Korean APT ScarCruft (ChinopuNK) executed a July phishing campaign in South Korea delivering a multi-stage payload — including a Rust backdoor using PubNub C2, various info-stealers, a ChillyChino variant, and a new VCD ransomware — indicating a shift from espionage-only operations toward blended financially motivated attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.