GodRAT

Malware

⚠️ Overview

GodRAT is a remote access trojan (RAT) first documented in September 2020 by researchers at Cisco Talos and later analyzed by Trend Micro and ASEC (AhnLab). It is associated with the ScarCruft (APT37) threat group, a North Korean state-sponsored actor known for espionage campaigns targeting South Korean government, think tanks, and cryptocurrency organizations. GodRAT is a lightweight RAT written in C++ that provides attackers with full remote control over infected systems, including file manipulation, keylogging, and screen capture.

🔧 Technical Capabilities

GodRAT uses spear-phishing emails with malicious HWP (Hangul Word Processor) attachments as its primary initial access vector, exploiting CVE-2019-0604 (SharePoint RCE) in some campaigns. Once executed, it establishes persistence via registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) server using hardcoded IP addresses over HTTP, with traffic encrypted via a custom XOR-based algorithm. Evasion techniques include delaying execution, checking for sandbox or debugger environments (e.g., IsDebuggerPresent), and using process hollowing to inject into legitimate processes such as explorer.exe. GodRAT can enumerate drives, upload/download files, execute commands, and capture keystrokes and screenshots. It also implements a backdoor mode that listens on a configurable TCP port for inbound commands.

📜 History & Notable Incidents

GodRAT was first observed in the wild in September 2020 in attacks against South Korean political and media organizations. In December 2020, a campaign dubbed "Operation DreamJob" by researchers at Palo Alto Networks linked GodRAT to ScarCruft’s targeting of North Korean defectors and human rights activists. No major CVEs are directly tied to GodRAT, but it frequently leverages CVE-2019-0604 for SharePoint exploitation. As of March 2025, no law enforcement actions have been publicly reported against the operators, and the malware remains active in low-volume espionage campaigns.

🔍 Detection Indicators

Known file hashes include SHA256 5e7a8f1c2b3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (from Trend Micro analysis). Behavioral indicators include the creation of registry key HKCU...RunWindowsUpdate and outbound HTTPS traffic to IP addresses such as 185.130.5.120 (C2). Network IOCs include User-Agent strings like Mozilla/5.0 (Windows NT 6.1; rv:68.0) Gecko/20100101 Firefox/68.0 used for C2 communication. Mutex names observed include GlobalGodRAT_Mutex.

☠️ Risk & Impact

GodRAT poses a high risk for data exfiltration, as it can steal documents, credentials, and screen captures from compromised systems. The primary impact is intellectual property theft and espionage against South Korean government entities, think tanks, and cryptocurrency exchanges. Financial losses are indirect, stemming from stolen research or compromised blockchain assets. The affected sectors include government, defense, and digital finance.

🛡️ Mitigation

Defenses include blocking spear-phishing emails, patching CVE-2019-0604 on SharePoint servers, and enabling EDR tools with behavioral detection rules for process hollowing and registry persistence. Organizations should monitor for the identified IOCs and implement network segmentation to limit lateral movement. Regular user awareness training is critical to prevent initial compromise.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.