HomeSecurityAPT37 targets South Korean journalists with Chinotto malware

APT37 targets South Korean journalists with Chinotto malware

North Korean state-run hacking group APT37 is targeting South Korean journalists, defectors and human rights activists through email, spear-phishing and attacks that deliver the Chinotto malware, capable of infecting Windows and Android devices.

APT37 targets South Korean journalists with Chinotto malware

The APT37 group (also known as Reaper) has been active since at least 2012 and is an advanced persistent threat (APT) group linked to the North Korean government.

Other security companies also monitor it as StarCruft (Kaspersky Lab), Group123 (Cisco Talos) or FreeMilk (Palo Alto Networks).

The group is known for targeting individuals of interest to the North Korean regime, including journalists, diplomats, and government officials.

Chinotto, the malware deployed in their most recent campaign – discovered by Kaspersky security researchers – allows the hacking group to control compromised devices, spy on users via screenshots, deploy additional payloads, collect data and upload it to servers controlled by the attackers.

As Kaspersky found, this backdoor was delivered to victims' devices months after the initial intrusions. In one incident, hackers waited up to six months before installing Chinotto, which allowed them to exfiltrate sensitive data from the infected device.

APT37 Chinotto

Chinotto is highly adaptable malware, as evidenced by the many variants found during campaign analysis, sometimes multiple payloads deployed on the same infected devices.

The Windows and Android variants of the malware use the same command-and-control communication pattern and send the stolen information to web servers located primarily in South Korea.

As Android variants request extensive permissions on compromised devices, once granted, Chinotto can use them to collect large amounts of sensitive data, including victims' contacts, text messages, call logs, device information, and even audio recordings.

If it also finds and steals the victim's credentials, it allows APT37 operators to reach other targets using the stolen credentials via email and social media.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS