New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs

2025-11-05 0x0v1

https://www.0x0v1.com/endclientrat/

Thumbnail for New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs

A Kimsuky-linked EndClient RAT campaign targeted North Korean human-rights defenders after an initial victim’s Google and KakaoTalk accounts were compromised and then used in manual one-to-one conversations to push a StressClear.msi lure. The MSI was signed with a certificate tied to a Chinese company and bundled an AutoIT-based RAT with Korean banking authentication software, while a false language-pack error acted as decoy behavior. The dropper places AutoIt3.exe and an obfuscated AU3 script under Public\Music, creates persistence with a scheduled task named IoKlTr and a Startup shortcut named Smart_Web.lnk, and checks a global mutex before continuing. The RAT connects to 116[.]202[.]99[.]218:443, beacons system details using an endClient9688 JSON marker, and uses paired client/server markers for command and file transfer. The low detection rates reported for the dropper and payload make the campaign especially important for civil-society defenders and DPRK-focused threat tracking.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7107c110e4694f50a39a91f8497b9f0… 2025-11-05 2026-01-22
IPv4 116.202.99.218 2025-11-05 2026-01-22
HASH abd73e21cabebdfecfff7294a6f8e4a… 2025-11-05 2025-11-05
HASH bcdd8a213cf6986bad4bb487fe1bf79… 2025-11-05 2025-11-05
HASH dfad5a2324e4bde8ba232d914fcea4c… 2025-11-05 2025-11-05

Related Actors

Related Reports

« Back