216.73.216.6

New Kimsuky Malware "EndClient RAT": Technical Report and IOCs

· Published 07/11/2025 09:08 · Modified 07/11/2025 10:10

Export JSON

Essential information

Published
07/11/2025 09:08
Modified
07/11/2025 10:10
Tags
2025-11-07 autoit c2 protocol code-signing endclient rat human rights defenders north korea persistence remote access trojan
Related entities
3 observables, 1 intrusion sets (apt), 1 malware, 1 others

Description

A novel (RAT) called '' has been discovered targeting North Korean . The malware, attributed to the Kimsuky group, is delivered via a signed Microsoft Installer package disguised as 'StressClear.msi'. It uses scripts for execution and establishes through scheduled tasks and startup folder entries. The RAT communicates with a command and control server using a custom protocol with JSON markers. It has capabilities for remote shell access, file upload/download, and system information gathering. The malware employs in-memory modules for binary search, Base64 encoding/decoding, and LZMA decompression. Detection rates for this malware are currently low, making public disclosure crucial for protecting affected communities.