Konni’s New Arsenal: Unmasking GSRAT in North Korea-linked APT Operation

2026-01-22 LAC

https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_9_takuma_matsumoto-yoshihiro_ishikawa_en.pdf

Attachments

JSAC2026_1_9_takuma_matsumoto-yoshihiro_ishikawa_en.pdf (5 MB)

Konni, described as a North Korea-related APT actor active since at least 2014, used a May 2025 spear-phishing campaign against organizations associated with Japanese financial interests to deploy a new AutoIt-based RAT named GSRAT. The infection chain used LNK files and AutoIt scripts: the LNK located powershell.exe, executed embedded obfuscated script, dropped a decoy, downloaded a CAB file from a compromised site, extracted files under C:\Users\Public\documents, and launched start.vbs to install the payload components. GSRAT, also referenced as EndRAT, EndClient RAT, or AutoItRAT, is a compiled AutoIt v3 payload that creates victim identifiers from host hardware details, communicates with C2 servers, and supports remote shell access, server-to-victim file delivery, victim-to-server file exfiltration, and directory listing. The excerpt also notes persistence through startup shortcuts or scheduled tasks, abuse of WordPress-based staging sites and VPS or hosting services for C2, and later observations of GSRAT distribution through KakaoTalk in South Korea.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bcf9044ac1c90206d8d8b7b98cf084d… 2026-01-22 2026-01-22
HASH 0c5b6081e73a500825eae5687961565… 2026-01-22 2026-01-22
HASH 8b396ba6861a39b1801b369eb461311… 2026-01-22 2026-01-22
HASH 22ddecca88cc964f4357458467acbcb… 2026-01-22 2026-01-22
HASH 4abfbbfa443e7be34da30abda466578… 2026-01-22 2026-01-22
HASH d3590bf0017815f77bd286b4c47f186… 2026-01-22 2026-01-22
HASH 0ecac57958e77648b5e5b47787612f9… 2026-01-22 2026-01-22
HASH 3b4a56b6d86393fa0c058cdd3d26809… 2026-01-22 2026-01-22
URL https://www.estsecurity.com/ent… 2026-01-22 2026-01-22
URL https://webapp-wdac-wizard.azur… 2026-01-22 2026-01-22
DOMAIN accuses.org 2026-01-22 2026-01-22
DOMAIN webapp-wdac-wizard.azurewebsite… 2026-01-22 2026-01-22
DOMAIN kpcserver.com 2026-01-22 2026-01-22
IPv4 23.254.225.184 2026-01-22 2026-01-22
IPv4 3.3.14.1 2026-01-22 2026-01-22
IPv4 3.1.0.15 2026-01-22 2026-01-22
IPv4 3.2.5.1 2026-01-22 2026-01-22
IPv4 3.3.14.2 2026-01-22 2026-01-22
IPv4 65.21.154.31 2026-01-22 2026-01-22
IPv4 3.3.6.1 2026-01-22 2026-01-22
IPv4 3.3.17.1 2026-01-22 2026-01-22
IPv4 3.3.8.1 2026-01-22 2026-01-22
IPv4 3.3.16.1 2026-01-22 2026-01-22
IPv4 38.180.249.56 2026-01-22 2026-01-22
IPv4 194.68.27.204 2026-01-22 2026-01-22
IPv4 91.107.208.93 2025-11-09 2026-01-22
IPv4 109.234.36.135 2025-11-09 2026-01-22
HASH 7107c110e4694f50a39a91f8497b9f0… 2025-11-05 2026-01-22
IPv4 116.202.99.218 2025-11-05 2026-01-22
HASH e9239ba649aec746e3c0088bc564004… 2025-04-03 2026-01-22
HASH 9e1a3653029b5378736ea1debba44cd… 2024-08-22 2026-01-22
IPv4 3.3.14.5 2024-08-22 2026-01-22
IPv4 185.231.154.22 2024-07-31 2026-01-22
IPv4 94.103.87.212 2024-07-31 2026-01-22
DOMAIN autoitscript.com 2024-07-12 2026-01-22
IPv4 93.183.93.185 2024-07-12 2026-01-22
IPv4 62.113.118.157 2024-07-08 2026-01-22

Related Actors

Related Reports

« Back