#JelusRAT

Malware/Tool

2026-01-22 • To the past and beyond: Andariel’s latest arsenal and cyberattacks

JelusRAT is a remote-access Trojan discovered by WithSecure in 2025 and attributed to the North Korea-linked Andariel group. It was one of three previously undocumented RATs, alongside StarshellRAT and GopherRAT, uncovered while investigating attacks against a European public or legal-sector organization and enterprise-resource-planning software in South Korea. The broader intrusions involved cyberespionage, staging infrastructure, privilege-escalation tools, and endpoint-defense evasion, but JelusRAT’s platform, commands, persistence, delivery mechanism, and command-and-control protocol were not individually described.

Tagged Reports

« Back