#KaolinRAT

Malware/Tool

2024-04-18 • From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams

KaolinRAT is a previously undocumented remote-access trojan found by Avast in a 2023 campaign that targeted selected technically skilled individuals in Asia with fabricated job offers. The malware provides standard RAT functionality and can also alter the last-write timestamp of a chosen file and load an arbitrary DLL received from its command-and-control server. Researchers assessed that it loaded the FudModule 2.0 rootkit together with a zero-day administrator-to-kernel exploit. The wider chain was associated with Lazarus tradecraft involving vulnerable drivers and rootkit techniques intended to blind security products.

Tagged Reports

« Back