#FileRATClient

Malware/Tool

2026-08-21 • Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto

FileRATClient is a JavaScript remote-access implant used in a late-2025 Konni campaign targeting cryptocurrency professionals on macOS. Delivered at the end of a multi-stage chain involving AppleScript lures, a fake system dialog, TCC permission manipulation, JavaScript reconnaissance, and LaunchAgent persistence, it supports screen streaming, keylogging, webcam access, file operations, browser control through the Chrome DevTools protocol, SOCKS5 proxying, remote command execution, and self-deletion. Its extensive comments, consistent formatting, and emoji-heavy logging were assessed as signs of AI-assisted development.

Tagged Reports

« Back