The Code Loom of Scarcruft: Stitching Ransomware into a Polyglot Intrusion
ID: c7efcb9a-7192-46f7-9a35-4495b67b3086
STIX ID: report--c7efcb9a-7192-46f7-9a35-4495b67b3086
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2025-08-07
Last Modified Date: 2025-08-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
S2W TALON reports a ScarCruft‑attributed campaign targeting South Korean users that used a malicious RAR/LNK phishing lure to deploy a multi‑stage toolchain: PubNub‑based backdoors (NubSpy), information stealers (FadeStealer, LightPeek), a Transacted Hollowing Python loader (TxPyLoader), a Rust reimplementation of CHILLYCHINO, and VCD ransomware that encrypts target directories; the report provides technical analysis, MITRE ATT&CK mappings, extensive IoCs (hashes, URLs, ransom email), and recommended detection/mitigation steps.
