#EndRAT
Malware/Tool
EndRAT, also known as GSRAT, EndClient RAT, or AutoItRAT, is a compiled AutoIt v3 remote access trojan used by the North Korea-linked Konni APT. It creates a ten-digit victim identifier from a SHA-256 hash of the computer name, CPU type, and storage volume identifier, and supports a remote shell, server-to-victim file transfer, file exfiltration, and directory listing. In Operation Poseidon, spear-phishing messages used advertising redirection URLs to lead targets to compressed archives containing malicious LNK files. Execution ultimately loaded EndRAT through an AutoIt script masquerading as a PDF, while compromised WordPress sites supported malware distribution and command-and-control infrastructure.
-
4
Tagged Reports
-
2
Unique Authors
-
5
Active Days