logo

ThreatLabz

ID: 3f6339e1-330f-5754-8056-bcb5b1a5d5db

STIX ID: report--3f6339e1-330f-5754-8056-bcb5b1a5d5db

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details APT37’s tactics for distributing the Chinotto PowerShell backdoor across multiple delivery mechanisms — including CHM files, a novel Excel XLL add-in, malicious LNK shortcuts, macro-enabled Office documents, and HWP files with embedded OLE objects — and provides technical analysis, file hashes, and metadata (e.g., VM MAC address, PDB path) useful for detection, attribution, and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.