TF-MAL-apk.chinotto
📛 Threat Title
Malware family: Chinotto
Description
ThreatFox malware family `apk.chinotto`. Printable name: Chinotto.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.chinotto
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.chinotto
IOC database
- Type
- domain
- Value
apk.chinotto- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.chinotto
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.chinotto
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:community.gurucul.com
The group leverages a single C2 server to control multiple malware components, including the newly discovered Rustonotto (aka CHILLYCHINO), a Rust-based backdoor active since June 2025; the long-used PowerShell backdoor Chinotto ; and FadeStealer, a surveillance tool that captures keystrokes, screenshots, audio, and removable media activity.
-
web:cyberpress.org
The campaign orchestrates three primary malware components through a single command-and-control server: Rustonotto, the newly identified Rust-compiled backdoor active since June 2025; Chinotto , a well-documented PowerShell backdoor operational since 2019; and FadeStealer, a comprehensive surveillance tool first discovered in 2023.
-
web:cybersecsentinel.com
Overview A novel campaign by North Korean-aligned APT37, active since at least 2012, has introduced a Rust-based backdoor named Rustonotto, alongside PowerShell loader Chinotto and data stealer FadeStealer. The infection chain begins with spear-phishing attachments, delivering malware via malicious Windows shortcut files or CHM help files, enabling stealth and persistence on Windows systems .
-
web:cybersecuritynews.com
APT37, the North Korean-aligned threat actor also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with sophisticated new malware targeting Windows systems. Active since 2012, the group primarily focuses on South Korean individuals connected to the North Korean regime or involved in human rights activism. The threat actor has now introduced a Rust-based backdoor ...
-
web:cybersixt.com
A new report reveals North Korea's APT37 is using Rust-based malware called Rustonotto, marking a shift toward modern languages and multi-platform attacks.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Chinotto malware family including references, samples and yara signatures.
-
web:www.auanet.org
The changes below constitute updates made in the 2025 Amendment:
-
web:www.fortiguard.com
FortiGuard Labs is aware of reports of recent activity from APT37. APT37 is a nation-state threat actor attributed to North Korea. The latest discovery by researchers at Kaspersky Labs has revealed a sophisticated, targeted attack that utilizes the stolen credentials from Facebook and email accounts belonging to an associate of the targeted victim.
-
web:www.kaspersky.co.uk
In a recent investigation, Kaspersky researchers uncovered a previously unknown malware dubbed Chinotto targeting North Korean defectors and human rights activists. The malware operated by an Advanced Persistent Threat (APT) actor ScarCruft is implemented in PowerShell, Windows executables, and Android apps. It is capable of controlling and exfiltrating sensitive information from its targets ...
-
web:www.zscaler.com
In recent campaigns, APT37 utilizes a single command-and-control (C2) server to orchestrate all components of their malware arsenal, including a Rust-based backdoor that ThreatLabz dubbed Rustonotto (also known as CHILLYCHINO), a PowerShell-based malware known as Chinotto , and FadeStealer.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.