216.73.216.36

Exploring a New KimJongRAT Stealer Variant and Its PowerShell Implementation

· Published 17/06/2025 20:39 · Modified 18/06/2025 11:57

Export JSON

Essential information

Published
17/06/2025 20:39
Modified
18/06/2025 11:57
Tags
2025-06-17 browser extensions content delivery network cryptocurrency kimjongrat multi-stage infection powershell stealer
Related entities
19 techniques (mitre), 1 malware

Description

This article analyzes two new variants of the : a Portable Executable (PE) variant and a implementation. Both variants use a process, starting with a Windows shortcut (LNK) file that downloads a dropper from a . The PE variant deploys a loader, decoy PDF, and text file, while the variant deploys a decoy PDF and ZIP archive containing scripts. Both variants gather victim information and browser data, including from crypto-wallet extensions. The variant focuses more on , searching for an extensive list of browser wallet extensions. The malware uses legitimate CDN services to mask its distribution and has evolved since its first appearance in 2013, showcasing the developers' commitment to updating its capabilities.

External references