North Korean Threat Actor Delivers Ransomware Via Phishing Emails

KnowBe4 Team | Aug 19, 2025

Modern Email AttacksThe North Korean threat actor ScarCruft has incorporated ransomware into its arsenal, according to researchers at South Korean security firm S2W.

ScarCruft is known for conducting espionage operations, but North Korean state-sponsored groups often conduct financially motivated attacks to generate revenue for Pyongyang.

“The deployment of ransomware, traditionally uncommon in ScarCruft campaigns, represents a notable deviation from the group’s historical focus on espionage,” the researchers write. “This suggests a potential shift toward financially motivated operations, or an expansion of operational goals that now include disruptive or extortion-driven tactics.”

The researchers observed the threat actor deploying ransomware in a campaign targeting South Koreans last month. The attackers sent phishing emails disguised as postal-code updates regarding changes in street addresses. The emails contained malicious LNK files embedded in RAR archives, which were designed to deliver a variety of different malware strains.

“Upon execution, the LNK dropped an AutoIt loader, which then fetched and executed additional payloads including a stealer, ransomware, and backdoor from an external server,” S2W says. “Among the nine distinct malware samples identified in this campaign, the following are the most notable: NubSpy, LightPeek, TxPyLoader, FadeStealer, VCD Ransomware, and CHILLYCHINO, among others.”

The threat actor has also ported its malware to new programming languages in order to expand targeting and evade detection.

“Existing malware, as well as publicly available code, has been ported to alternative programming languages for reuse,” the researchers write.

“Similar to the group’s prior use of Go-based malware like AblyGo, this campaign features malware written in Rust, suggesting a pattern of using modern languages for enhanced versatility and detection evasion. These efforts indicate ScarCruft’s ongoing focus on detection evasion and tooling.”

AI-powered security awareness training can give your organization an essential layer of defense against phishing attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

The Record has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.