logo

APT37: Rust Backdoor & Python Loader

ID: 515881a4-d97f-56d5-b0d6-730e2b141c06

STIX ID: report--515881a4-d97f-56d5-b0d6-730e2b141c06

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-09-16

Date Updated: 2026-05-01

...
...

**Executive Summary:** This technical analysis documents an APT37 multi-stage campaign that delivers Chinotto (PowerShell backdoor), Rustonotto (Rust C2 agent), and FadeStealer (data-stealer) via malicious Windows shortcut (LNK), CHM help files, and CAB/RAR payloads; the actor uses scheduled tasks, Base64-encoded C2 communication to a PHP backend, and advanced injection techniques (Transacted NTFS / Process Doppelgänging) to persist, surveil (keystrokes, screenshots, audio, device contents), and exfiltrate sensitive files in passworded RAR archives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.