Chinotto (Windows)

Malware type
rat
Profile updated
2026-07-07 14:05:05

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp

Context

Chinotto is a remote access trojan (RAT) associated with espionage activities linked to APT37, often targeting organizations in South Korea and Japan. It enables attackers to execute commands, capture screenshots, and harvest sensitive data.

Reports & references

  • Kaspersky — 105074 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Chinotto (report)
  • thorcert.notion.site — Ttps 9 F04Ce99784874947978Bd2947738Ac92 (report)
  • blog.sekoia.io — Peeking At Reaper Surveillance Operations Against North Korea Defectors (report)
  • zscaler.com — Unintentional Leak Glimpse Attack Vectors Apt37 (report)
  • boho.or.kr — Reportview.Do (report)
  • threatmon.io — Chinotto Backdoor Technical Analysis Of The Apt Reapers Powerful (report)

External references