#EndClientRAT

Malware/Tool

2025-11-05 • New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs

EndClientRAT is a remote-access trojan associated with Kimsuky and implemented around the AutoIt runtime. Its on-disk components consist of AutoIt code interpreted during execution, while additional functionality operates directly in memory. This split design lets the malware combine file-based scripts with memory-resident behavior as part of the same remote-access workflow. EndClientRAT therefore represents an AutoIt-based Kimsuky tool whose execution flow spans persistent components on disk and follow-on functionality loaded or maintained in memory.

Tagged Reports

« Back