New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
2025-11-05 • 0x0v1 •
A Kimsuky-linked EndClient RAT campaign targeted North Korean human-rights defenders after an initial victim’s Google and KakaoTalk accounts were compromised and then used in manual one-to-one conversations to push a StressClear.msi lure. The MSI was signed with a certificate tied to a Chinese company and bundled an AutoIT-based RAT with Korean banking authentication software, while a false language-pack error acted as decoy behavior. The dropper places AutoIt3.exe and an obfuscated AU3 script under Public\Music, creates persistence with a scheduled task named IoKlTr and a Startup shortcut named Smart_Web.lnk, and checks a global mutex before continuing. The RAT connects to 116[.]202[.]99[.]218:443, beacons system details using an endClient9688 JSON marker, and uses paired client/server markers for command and file transfer. The low detection rates reported for the dropper and payload make the campaign especially important for civil-society defenders and DPRK-focused threat tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7107c110e4694f50a39a91f8497b9f0… | 2025-11-05 | 2026-01-22 |
| IPv4 | 116.202.99.218 | 2025-11-05 | 2026-01-22 |
| HASH | abd73e21cabebdfecfff7294a6f8e4a… | 2025-11-05 | 2025-11-05 |
| HASH | bcdd8a213cf6986bad4bb487fe1bf79… | 2025-11-05 | 2025-11-05 |
| HASH | dfad5a2324e4bde8ba232d914fcea4c… | 2025-11-05 | 2025-11-05 |