The North Korea -linked APT37 group , also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with new, sophisticated malware targeting Windows systems .

Since 2012, the group has focused primarily on South Korean associated with the North Korean regime or involved in human rights advocacy activities.
The threat actor has now introduced a new Rust- based backdoor , dubbed Rustonotto , and has also leveraged its Python-based injection techniques to deploy the FadeStealer monitoring tool .
The latest campaign shows APT37's evolution in adopting modern programming languages and advanced injection techniques.
See also: Autonomous AI ransomware attacks are coming
APT37: New malware and infection techniques
The attack chain begins with spear-phishing emails containing malicious Windows shortcut files or Compiled HTML Help (CHM) files. These initial vectors lead to the deployment of multiple malware components that are orchestrated through a single command-and-control server.

The integration of the Rust programming language represents a significant change for the team, potentially allowing for cross-platform attacks while maintaining the functionality of a lightweight backdoor.
Zscaler researchers identified this sophisticated malware cluster , operating since June 2025, revealing the group's continued improvement in social engineering tactics and technical capabilities.
The campaign uses Transactional NTFS (TxF) for hidden code injection, demonstrating advanced evasion techniques. Researchers observed APT37 using vulnerable web servers as a C2 infrastructure, using a single PHP script to control the entire malware toolkit, including Rustonotto, Chinotto, and FadeStealer.
See also: From MostereRAT to ClickFix: New malware campaigns
The chain of infection in more detail
The attack methodology involves multiple stages of payload delivery and execution. As mentioned earlier, the initial breach occurs either through Windows shortcut files with PowerShell scripts or through CHM files that establish registry persistence mechanisms.
These actors then deploy the Rustonotto backdoor, which acts as a lightweight command executor, capable of receiving Base64-encoded Windows commands and returning the execution results to the threat actor's infrastructure.
The most sophisticated aspect of this campaign involves deploying FadeStealer via a Python-based injection mechanism, which uses Process Doppelgänging. The threat actor delivers malicious payloads packaged in Microsoft Cabinet files, which contain three critical components: a legitimate Python module renamed to tele_update.exe, a compiled Python module (tele.conf) responsible for decryption and injection, and the encrypted FadeStealer payload (tele.dat).

The Python injection script (TransactedHollowing.py) uses the Windows Transactional NTFS APIs to create temporary files within transactional contexts. The decryption routine extracts XOR keys from the payload and applies custom decryption algorithms to reveal the final executable.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Process Doppelgänging technique involves creating section objects from transacted files, mapping them to suspended legitimate processes, and manipulating thread contexts to redirect execution flow.
See also: LunaLock ransomware attacks artists
FadeStealer acts as a comprehensive monitoring tool, performing real-time keystroke logging, capturing screenshots every 30 seconds, recording 5-minute audio sessions, and monitoring USB devices every hour. The malware creates timestamped archives with hardcoded password protection, using built-in RAR tools for data compression and extraction via HTTP POST requests with multipart form data.
APT37: The key elements of the new attacks
| Malware Component | Programming Language | Primary Function | Persistence Method | Communication |
|---|---|---|---|---|
| Rustonotto | Rust | Lightweight backdoor | Scheduled Task (Microsoft Update) | HTTP with Base64 encoding |
| Chinotto | PowerShell | Command execution and file operations | Registry Run key | HTTP POST requests |
| FadeStealer | Windows PE (via Python injection) | Surveillance and data exfiltration | Registry Run key (TeleUpdate) | HTTP multipart uploads |
| Python Loader | Python | Process injection and payload deployment | Embedded in legitimate processes | Local file operations |
The technical sophistication of the campaign combined with targeted social engineering demonstrates APT37's continued evolution and the persistent threat to individuals and organizations associated with North Korean affairs.
