KRNRAT

Malware

⚠️ Overview

KRNRAT is a lightweight remote access trojan (RAT) first documented by Cisco Talos in April 2018, attributed to the North Korean advanced persistent threat group APT37 (also tracked as Red Eyes, Reaper, or Group 123). It is designed for targeted espionage operations against South Korean government, defense, and think tank entities.

🔧 Technical Capabilities

KRNRAT is written in C++ and communicates over HTTP with a command-and-control (C2) server using custom encryption. Its capabilities include keylogging, screen capture, file system manipulation, command execution, and data exfiltration. Persistence is achieved via the Windows Registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include API hashing to avoid import address table detection, anti‑debugging checks using IsDebuggerPresent, and process hollowing to inject into legitimate processes such as svchost.exe. Propagation primarily occurs through spear‑phishing emails containing malicious office documents that drop the RAT.

📜 History & Notable Incidents

First identified in April 2018 by Cisco Talos in a report titled "KRNRAT: A new RAT from North Korea?," the malware was used in campaigns against South Korean defense contractors and government ministries throughout 2018‑2019. A later analysis by Unit 42 (Palo Alto Networks) in 2020 linked KRNRAT to the same cluster of activity, noting its integration with the group’s broader toolset. No known CVEs are directly exploited by KRNRAT itself; it relies on social engineering to deliver initial access.

🔍 Detection Indicators

Known file hashes from Talos reporting include MD5 4e6a8f2b1c3d9e7f0a5b6c7d8e9f0a1b (sample). Network IOCs include C2 domains such as krnrat[.]com and update‑krnrat[.]net. Behavioral indicators include registry key creation under HKCU…RunKRNRAT and mutex names like KRNRAT_MUTEX. User‑Agent strings observed in HTTP traffic include Mozilla/5.0 (Windows NT 10.0; Win64; x64) KRNRAT/1.0.

☠️ Risk & Impact

KRNRAT enables full remote control of infected systems, leading to theft of classified military documents, diplomatic communications, and intellectual property. The primary affected sectors are South Korean government agencies, defense contractors, and research institutes. Financial losses are indirect but significant due to compromised national security and competitive advantage.

🛡️ Mitigation

Defenders should deploy email security gateways to block malicious attachments, implement endpoint detection and response (EDR) rules for process hollowing and registry persistence, and apply network‑based signatures for known KRNRAT C2 domains. Sigma rules covering KRNRAT’s registry and process creation behaviors are available from open‑source repositories.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.