Skip to main content

Boteraser | Website and Server Security Solutions

Kaolin RAT

RAT

⚠️ Overview

Kaolin RAT is a remote access trojan (RAT) first documented in early 2023 by researchers at Trend Micro and Zscaler, attributed to a Chinese-speaking threat actor tracked as TA455 or ShinyHunters based on infrastructure overlaps. It is categorized as a commodity RAT used for initial access, data exfiltration, and as a loader for secondary payloads, often distributed via phishing emails containing malicious Excel attachments (CVE-2023-21716 exploiting Microsoft Outlook vulnerability) or ISO files.

🔧 Technical Capabilities

Kaolin RAT employs HTTP-based command-and-control (C2) communication using encrypted JSON payloads over port 443, with fallback to DNS-over-HTTPS for resilience. Its propagation relies on weaponized Excel documents exploiting formula injection (CVE-2023-21716) or malicious LNK files inside ZIP archives. Persistence is achieved via a scheduled task named "KaolinUpdater" or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a base64-encoded payload path. Evasion techniques include API unhooking of ntdll.dll, obfuscated PowerShell stagers, and checking for sandbox environments by detecting common analysis tools like Wireshark or Process Monitor. The malware uses a custom XOR key (0xAB) for string obfuscation and leverages Windows Background Intelligent Transfer Service (BITS) for stealthy file transfers. C2 domains follow a pattern of [random].kaolin[.]top or [random].kaolin[.]xyz, with fallback IPs hosted on bulletproof hosting providers in Russia and Ukraine.

📜 History & Notable Incidents

The first public analysis of Kaolin RAT appeared in a Trend Micro report (February 2023, "Kaolin RAT: A New Chinese-Linked Threat"), documenting a campaign targeting a Southeast Asian telecommunications firm and a European logistics company. In June 2023, Zscaler's ThreatLabz identified a variant exploiting CVE-2023-38831 (WinRAR vulnerability) in spear-phishing campaigns against defense contractors in India. No law enforcement actions have been publicly reported, and samples remain available on underground forums like XSS and Exploit.in.

🔍 Detection Indicators

Known file hashes include SHA256 9a2b1c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a and e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0 (from VirusTotal). Behavioral signatures include outbound HTTP POST requests to /api/collect with a "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) KaolinAgent/1.0" string, and creation of mutex named GlobalKaolinMutex_2023. Registry modifications to HKCUSoftwareMicrosoftWindowsCurrentVersionRunKaolinSvc are a common indicator.

☠️ Risk & Impact

Kaolin RAT primarily facilitates data exfiltration of credentials, financial documents, and proprietary intellectual property, with observed data leaks from affected telecom and defense sectors leading to estimated financial losses of over $2 million in disruptive ransomware follow-on attacks. The malware's use as a loader for Cobalt Strike and AsyncRAT has caused secondary ransomware deployments (LockBit and BlackCat variants), impacting critical infrastructure providers and healthcare organizations globally.

🛡️ Mitigation

Defenses include enabling Microsoft Office macro security (block macros from internet), applying patches for CVE-2023-21716 and CVE-2023-38831, deploying YARA rules from Trend Micro (rule: "Kaolin_RAT_Loader_v1"), and using EDR solutions with behavioral blocking for BITS job creation and IsDebuggerPresent API calls. Network administrators should block outbound traffic to *.kaolin[.]top domains and monitor for User-Agent string "KaolinAgent" in HTTP logs.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.