s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.chinotto

📛 Threat Title

Malware family: Chinotto

Category: Chinotto First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.chinotto`. Printable name: Chinotto.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.chinotto VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.chinotto

IOC database

Type
domain
Value
apk.chinotto
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.chinotto

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.chinotto

References (1)

Remediations (10)

  • web:community.gurucul.com

    The group leverages a single C2 server to control multiple malware components, including the newly discovered Rustonotto (aka CHILLYCHINO), a Rust-based backdoor active since June 2025; the long-used PowerShell backdoor Chinotto ; and FadeStealer, a surveillance tool that captures keystrokes, screenshots, audio, and removable media activity.

  • web:cyberpress.org

    The campaign orchestrates three primary malware components through a single command-and-control server: Rustonotto, the newly identified Rust-compiled backdoor active since June 2025; Chinotto , a well-documented PowerShell backdoor operational since 2019; and FadeStealer, a comprehensive surveillance tool first discovered in 2023.

  • web:cybersecsentinel.com

    Overview A novel campaign by North Korean-aligned APT37, active since at least 2012, has introduced a Rust-based backdoor named Rustonotto, alongside PowerShell loader Chinotto and data stealer FadeStealer. The infection chain begins with spear-phishing attachments, delivering malware via malicious Windows shortcut files or CHM help files, enabling stealth and persistence on Windows systems .

  • web:cybersecuritynews.com

    APT37, the North Korean-aligned threat actor also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with sophisticated new malware targeting Windows systems. Active since 2012, the group primarily focuses on South Korean individuals connected to the North Korean regime or involved in human rights activism. The threat actor has now introduced a Rust-based backdoor ...

  • web:cybersixt.com

    A new report reveals North Korea's APT37 is using Rust-based malware called Rustonotto, marking a shift toward modern languages and multi-platform attacks.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Chinotto malware family including references, samples and yara signatures.

  • web:www.auanet.org

    The changes below constitute updates made in the 2025 Amendment:

  • web:www.fortiguard.com

    FortiGuard Labs is aware of reports of recent activity from APT37. APT37 is a nation-state threat actor attributed to North Korea. The latest discovery by researchers at Kaspersky Labs has revealed a sophisticated, targeted attack that utilizes the stolen credentials from Facebook and email accounts belonging to an associate of the targeted victim.

  • web:www.kaspersky.co.uk

    In a recent investigation, Kaspersky researchers uncovered a previously unknown malware dubbed Chinotto targeting North Korean defectors and human rights activists. The malware operated by an Advanced Persistent Threat (APT) actor ScarCruft is implemented in PowerShell, Windows executables, and Android apps. It is capable of controlling and exfiltrating sensitive information from its targets ...

  • web:www.zscaler.com

    In recent campaigns, APT37 utilizes a single command-and-control (C2) server to orchestrate all components of their malware arsenal, including a Rust-based backdoor that ThreatLabz dubbed Rustonotto (also known as CHILLYCHINO), a PowerShell-based malware known as Chinotto , and FadeStealer.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.