216.73.216.6

Technical Analysis of kkRAT

· Published 10/09/2025 18:49 · Modified 10/09/2025 20:40

Export JSON

Essential information

Published
10/09/2025 18:49
Modified
10/09/2025 20:40
Tags
2025-09-10 big bad wolf byovd chinese-speaking fatalrat ghost rat kkrat remote access trojan valleyrat
Related entities
17 techniques (mitre), 1 others

Description

A malware campaign targeting users has been identified, delivering three types of malware: , , and . The campaign uses fake installer pages to distribute the malware. , a new , shares similarities with and . It employs advanced evasion techniques, including sandbox detection and anti-analysis methods. The malware uses the technique to disable antivirus and EDR systems. 's features include clipboard manipulation for cryptocurrency address replacement and deployment of remote monitoring tools. The malware's network communication protocol is similar to 's but with added encryption. supports multiple plugins and commands for various malicious activities.

External references