#EndRAT

Malware/Tool

2026-01-18 • 포세이돈 작전: 구글 광고 리다이렉션 메커니즘을 악용한 스피어 피싱 공격

EndRAT, also known as GSRAT, EndClient RAT, or AutoItRAT, is a compiled AutoIt v3 remote access trojan used by the North Korea-linked Konni APT. It creates a ten-digit victim identifier from a SHA-256 hash of the computer name, CPU type, and storage volume identifier, and supports a remote shell, server-to-victim file transfer, file exfiltration, and directory listing. In Operation Poseidon, spear-phishing messages used advertising redirection URLs to lead targets to compressed archives containing malicious LNK files. Execution ultimately loaded EndRAT through an AutoIt script masquerading as a PDF, while compromised WordPress sites supported malware distribution and command-and-control infrastructure.

Tagged Reports

« Back