#KimjongRAT
Malware/Tool
KimjongRAT is a Windows remote-access trojan and information stealer associated with Kimsuky and reported in use since around 2013. Recent campaigns used phishing messages impersonating South Korean public bodies, shortened links, ZIP archives hosted on GitHub Releases, and LNK files disguised as documents. Opening the lure invoked mshta to retrieve an obfuscated HTA/VBScript loader, which displayed a decoy PDF, checked Windows Defender, and downloaded later stages from attacker-controlled Google Drive. Reported collection includes system and browser data, browser encryption keys, cryptocurrency-wallet information, Telegram, and Discord artifacts. Newer variants retain theft functions while deploying a MeshCentral-based agent for remote access, reflecting continued expansion toward sustained control of compromised systems.
-
8
Tagged Reports
-
6
Unique Authors
-
4,764
Active Days