#xRAT

Malware/Tool

2022-01-28 • Kimsuky 그룹의 xRAT(Quasar RAT) 유포 정황

xRAT is an open-source remote-access Trojan used by Kimsuky in multi-stage espionage operations. It provides keylogging, remote shell access, and file-management functions, enabling initial collection and interactive control of compromised Windows systems. Documented campaigns combined it with the custom Gold Dragon backdoor, which established persistence and performed additional exfiltration, and related reporting places xRAT alongside RandomQuery and FlowerPower. Its commodity availability means the malware alone is not a reliable indicator of Kimsuky attribution.

Tagged Reports

« Back