logo

APT37 Deploys New Android Spyware, Chinotto

ID: 1873d4d8-ee86-5936-bfd5-7f0a1c40c90c

STIX ID: report--1873d4d8-ee86-5936-bfd5-7f0a1c40c90c

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-05-20

Date Updated: 2026-07-17

...
...

This report analyzes 'Chinotto', an Android spyware sample attributed to North Korean APT37 (Reaper/Ricochet Chollima), describing how the app (SecureTalk, package com.private.talk) requests dangerous permissions to stealthily harvest contacts, SMS, call logs, device/account info, media and audio, and exfiltrates collected data to a C2 (http://haeundaejugong.com/…). The analysis includes manifest and source-code excerpts, observed commands, a SHA256 hash of the malicious APK, infrastructure notes (hosting in South Korea, fast-flux indicator), IOCs, and recommended mitigations for users and banks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.