HomeSecurityAPT37 Targets Windows with New Rust & Python Based Malware

APT37 Targets Windows with New Rust & Python Based Malware

The North Korea -linked APT37 group , also known as ScarCruft, Ruby Sleet, and Velvet Chollima, has expanded its arsenal with new, sophisticated malware targeting Windows systems .

APT37 Windows Rust & Python Based Malware

Since 2012, the group has focused primarily on South Korean associated with the North Korean regime or involved in human rights advocacy activities.

The threat actor has now introduced a new Rust- based backdoor , dubbed Rustonotto , and has also leveraged its Python-based injection techniques to deploy the FadeStealer monitoring tool .

The latest campaign shows APT37's evolution in adopting modern programming languages ​​and advanced injection techniques.

See also: Autonomous AI ransomware attacks are coming

APT37: New malware and infection techniques

The attack chain begins with spear-phishing emails containing malicious Windows shortcut files or Compiled HTML Help (CHM) files. These initial vectors lead to the deployment of multiple malware components that are orchestrated through a single command-and-control server.

APT37 Targets Windows with New Rust & Python Based Malware

The integration of the Rust programming language represents a significant change for the team, potentially allowing for cross-platform attacks while maintaining the functionality of a lightweight backdoor.

Zscaler researchers identified this sophisticated malware cluster , operating since June 2025, revealing the group's continued improvement in social engineering tactics and technical capabilities.

The campaign uses Transactional NTFS (TxF) for hidden code injection, demonstrating advanced evasion techniques. Researchers observed APT37 using vulnerable web servers as a C2 infrastructure, using a single PHP script to control the entire malware toolkit, including Rustonotto, Chinotto, and FadeStealer.

See also: From MostereRAT to ClickFix: New malware campaigns

The chain of infection in more detail

The attack methodology involves multiple stages of payload delivery and execution. As mentioned earlier, the initial breach occurs either through Windows shortcut files with PowerShell scripts or through CHM files that establish registry persistence mechanisms.

These actors then deploy the Rustonotto backdoor, which acts as a lightweight command executor, capable of receiving Base64-encoded Windows commands and returning the execution results to the threat actor's infrastructure.

The most sophisticated aspect of this campaign involves deploying FadeStealer via a Python-based injection mechanism, which uses Process Doppelgänging. The threat actor delivers malicious payloads packaged in Microsoft Cabinet files, which contain three critical components: a legitimate Python module renamed to tele_update.exe, a compiled Python module (tele.conf) responsible for decryption and injection, and the encrypted FadeStealer payload (tele.dat).

APT37 Targets Windows with New Rust & Python Based Malware

The Python injection script (TransactedHollowing.py) uses the Windows Transactional NTFS APIs to create temporary files within transactional contexts. The decryption routine extracts XOR keys from the payload and applies custom decryption algorithms to reveal the final executable.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Process Doppelgänging technique involves creating section objects from transacted files, mapping them to suspended legitimate processes, and manipulating thread contexts to redirect execution flow.

See also: LunaLock ransomware attacks artists

FadeStealer acts as a comprehensive monitoring tool, performing real-time keystroke logging, capturing screenshots every 30 seconds, recording 5-minute audio sessions, and monitoring USB devices every hour. The malware creates timestamped archives with hardcoded password protection, using built-in RAR tools for data compression and extraction via HTTP POST requests with multipart form data.

APT37: The key elements of the new attacks

Malware ComponentProgramming LanguagePrimary FunctionPersistence MethodCommunication
RustonottoRustLightweight backdoorScheduled Task (Microsoft Update)HTTP with Base64 encoding
ChinottoPowerShellCommand execution and file operationsRegistry Run keyHTTP POST requests
FadeStealerWindows PE (via Python injection)Surveillance and data exfiltrationRegistry Run key (TeleUpdate)HTTP multipart uploads
Python LoaderPythonProcess injection and payload deploymentEmbedded in legitimate processesLocal file operations

The technical sophistication of the campaign combined with targeted social engineering demonstrates APT37's continued evolution and the persistent threat to individuals and organizations associated with North Korean affairs.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS