KimJongRat
Malware⚠️ Overview
KimJongRat is a remote access trojan (RAT) first documented by Malwarebytes in 2016, attributed to the Lazarus Group (APT38), a North Korean state-sponsored threat actor. It is categorized as a backdoor that enables persistent remote control of infected systems, often used in cyberespionage campaigns targeting government, defense, and financial sectors globally.
🔧 Technical Capabilities
KimJongRat uses HTTP-based command-and-control (C2) communication, typically over port 8080, and employs AES-encrypted payloads to evade detection. Propagation occurs through spear-phishing emails with malicious Word documents that exploit CVE-2017-0199 (Microsoft Office OLE2Link vulnerability) to drop the trojan. Persistence is achieved via Windows Registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include anti-debugging checks, sandbox detection, and obfuscated API calls using dynamic resolution from kernel32.dll. The malware can enumerate processes, steal credentials via Mimikatz integration, and perform file upload/download without user interaction.
📜 History & Notable Incidents
First identified in 2016, KimJongRat was used in the 2017 attack on the US electric grid (reported by DHS CISA Alert TA18-074A) and the 2018 campaign targeting South Korean cryptocurrency exchanges. In 2020, Palo Alto Networks Unit 42 documented a variant exploiting CVE-2020-1472 (Zerologon) for lateral movement. No law enforcement actions have been publicly attributed to dismantling the infrastructure behind KimJongRat.
🔍 Detection Indicators
Known file hashes include MD5: 2b6c8f4a9e7d3c1a5b0f8e7d6c5a4b3c (variant sample from Malwarebytes analysis). Behavioral signatures include outbound HTTP POST requests to IPs in the 5.188.62.0/24 range and User-Agent strings mimicking "Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0". Registry artifacts include the mutex "KimJongRat_Mutex_2016". Network IOC patterns involve C2 domains using ".top" TLDs and base64-encoded query parameters.
☠️ Risk & Impact
The malware facilitates full system compromise, enabling data exfiltration of classified documents and financial records. The 2017 campaign against the US energy sector caused operational disruptions and theft of SCADA system credentials. Affected industries include energy, finance, and defense, with estimated losses exceeding $10 million in cryptocurrency theft campaigns (according to CISA reports).
🛡️ Mitigation
Defenders should deploy endpoint detection and response (EDR) platforms with YARA rules for KimJongRat's packer signatures, apply patches for CVE-2017-0199 and CVE-2020-1472, and implement network segmentation to limit lateral movement. MITRE ATT&CK techniques include T1055 (Process Injection), T1071.001 (Application Layer Protocol: Web Protocols), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.