Konni’s New Arsenal: Unmasking GSRAT in North Korea-linked APT Operation
2026-01-22 • LAC •
https://jsac.jpcert.or.jp/archive/2026/pdf/JSAC2026_1_9_takuma_matsumoto-yoshihiro_ishikawa_en.pdf
Attachments
Konni, described as a North Korea-related APT actor active since at least 2014, used a May 2025 spear-phishing campaign against organizations associated with Japanese financial interests to deploy a new AutoIt-based RAT named GSRAT. The infection chain used LNK files and AutoIt scripts: the LNK located powershell.exe, executed embedded obfuscated script, dropped a decoy, downloaded a CAB file from a compromised site, extracted files under C:\Users\Public\documents, and launched start.vbs to install the payload components. GSRAT, also referenced as EndRAT, EndClient RAT, or AutoItRAT, is a compiled AutoIt v3 payload that creates victim identifiers from host hardware details, communicates with C2 servers, and supports remote shell access, server-to-victim file delivery, victim-to-server file exfiltration, and directory listing. The excerpt also notes persistence through startup shortcuts or scheduled tasks, abuse of WordPress-based staging sites and VPS or hosting services for C2, and later observations of GSRAT distribution through KakaoTalk in South Korea.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bcf9044ac1c90206d8d8b7b98cf084d… | 2026-01-22 | 2026-01-22 |
| HASH | 0c5b6081e73a500825eae5687961565… | 2026-01-22 | 2026-01-22 |
| HASH | 8b396ba6861a39b1801b369eb461311… | 2026-01-22 | 2026-01-22 |
| HASH | 22ddecca88cc964f4357458467acbcb… | 2026-01-22 | 2026-01-22 |
| HASH | 4abfbbfa443e7be34da30abda466578… | 2026-01-22 | 2026-01-22 |
| HASH | d3590bf0017815f77bd286b4c47f186… | 2026-01-22 | 2026-01-22 |
| HASH | 0ecac57958e77648b5e5b47787612f9… | 2026-01-22 | 2026-01-22 |
| HASH | 3b4a56b6d86393fa0c058cdd3d26809… | 2026-01-22 | 2026-01-22 |
| URL | https://www.estsecurity.com/ent… | 2026-01-22 | 2026-01-22 |
| URL | https://webapp-wdac-wizard.azur… | 2026-01-22 | 2026-01-22 |
| DOMAIN | accuses.org | 2026-01-22 | 2026-01-22 |
| DOMAIN | webapp-wdac-wizard.azurewebsite… | 2026-01-22 | 2026-01-22 |
| DOMAIN | kpcserver.com | 2026-01-22 | 2026-01-22 |
| IPv4 | 23.254.225.184 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.3.14.1 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.1.0.15 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.2.5.1 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.3.14.2 | 2026-01-22 | 2026-01-22 |
| IPv4 | 65.21.154.31 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.3.6.1 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.3.17.1 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.3.8.1 | 2026-01-22 | 2026-01-22 |
| IPv4 | 3.3.16.1 | 2026-01-22 | 2026-01-22 |
| IPv4 | 38.180.249.56 | 2026-01-22 | 2026-01-22 |
| IPv4 | 194.68.27.204 | 2026-01-22 | 2026-01-22 |
| IPv4 | 91.107.208.93 | 2025-11-09 | 2026-01-22 |
| IPv4 | 109.234.36.135 | 2025-11-09 | 2026-01-22 |
| HASH | 7107c110e4694f50a39a91f8497b9f0… | 2025-11-05 | 2026-01-22 |
| IPv4 | 116.202.99.218 | 2025-11-05 | 2026-01-22 |
| HASH | e9239ba649aec746e3c0088bc564004… | 2025-04-03 | 2026-01-22 |
| HASH | 9e1a3653029b5378736ea1debba44cd… | 2024-08-22 | 2026-01-22 |
| IPv4 | 3.3.14.5 | 2024-08-22 | 2026-01-22 |
| IPv4 | 185.231.154.22 | 2024-07-31 | 2026-01-22 |
| IPv4 | 94.103.87.212 | 2024-07-31 | 2026-01-22 |
| DOMAIN | autoitscript.com | 2024-07-12 | 2026-01-22 |
| IPv4 | 93.183.93.185 | 2024-07-12 | 2026-01-22 |
| IPv4 | 62.113.118.157 | 2024-07-08 | 2026-01-22 |