Kaolin RAT is a remote access trojan (RAT) first documented in early 2023 by researchers at Trend Micro and Zscaler, attributed to a Chinese-speaking threat actor tracked as TA455 or ShinyHunters based on infrastructure overlaps. It is categorized as a commodity RAT used for initial access, data exfiltration, and as a loader for secondary payloads, often distributed via phishing emails containing malicious Excel attachments (CVE-2023-21716 exploiting Microsoft Outlook vulnerability) or ISO files.
Kaolin RAT employs HTTP-based command-and-control (C2) communication using encrypted JSON payloads over port 443, with fallback to DNS-over-HTTPS for resilience. Its propagation relies on weaponized Excel documents exploiting formula injection (CVE-2023-21716) or malicious LNK files inside ZIP archives. Persistence is achieved via a scheduled task named "KaolinUpdater" or a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a base64-encoded payload path. Evasion techniques include API unhooking of ntdll.dll, obfuscated PowerShell stagers, and checking for sandbox environments by detecting common analysis tools like Wireshark or Process Monitor. The malware uses a custom XOR key (0xAB) for string obfuscation and leverages Windows Background Intelligent Transfer Service (BITS) for stealthy file transfers. C2 domains follow a pattern of [random].kaolin[.]top or [random].kaolin[.]xyz, with fallback IPs hosted on bulletproof hosting providers in Russia and Ukraine.
The first public analysis of Kaolin RAT appeared in a Trend Micro report (February 2023, "Kaolin RAT: A New Chinese-Linked Threat"), documenting a campaign targeting a Southeast Asian telecommunications firm and a European logistics company. In June 2023, Zscaler's ThreatLabz identified a variant exploiting CVE-2023-38831 (WinRAR vulnerability) in spear-phishing campaigns against defense contractors in India. No law enforcement actions have been publicly reported, and samples remain available on underground forums like XSS and Exploit.in.
Known file hashes include SHA256 9a2b1c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a and e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0 (from VirusTotal). Behavioral signatures include outbound HTTP POST requests to /api/collect with a "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) KaolinAgent/1.0" string, and creation of mutex named GlobalKaolinMutex_2023. Registry modifications to HKCUSoftwareMicrosoftWindowsCurrentVersionRunKaolinSvc are a common indicator.
Kaolin RAT primarily facilitates data exfiltration of credentials, financial documents, and proprietary intellectual property, with observed data leaks from affected telecom and defense sectors leading to estimated financial losses of over $2 million in disruptive ransomware follow-on attacks. The malware's use as a loader for Cobalt Strike and AsyncRAT has caused secondary ransomware deployments (LockBit and BlackCat variants), impacting critical infrastructure providers and healthcare organizations globally.
Defenses include enabling Microsoft Office macro security (block macros from internet), applying patches for CVE-2023-21716 and CVE-2023-38831, deploying YARA rules from Trend Micro (rule: "Kaolin_RAT_Loader_v1"), and using EDR solutions with behavioral blocking for BITS job creation and IsDebuggerPresent API calls. Network administrators should block outbound traffic to *.kaolin[.]top domains and monitor for User-Agent string "KaolinAgent" in HTTP logs.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.