KSREMOTE is a remote access trojan (RAT) first documented in September 2023 by the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). It is associated with the cyber espionage group APT-C-60 (also tracked as TA4569), likely operating from China, and is frequently deployed as a secondary payload following an initial infection via spear-phishing campaigns. The malware is categorized under the RAT family and is primarily used for persistent remote access and data exfiltration in targeted attacks against defense, technology, and government sectors.
KSREMOTE employs process injection and DLL sideloading to evade detection, often loading malicious code into legitimate Windows processes such as svchost.exe or explorer.exe. It utilizes encrypted C2 communication over HTTPS, with domains mimicking legitimate services like Microsoft or Adobe updates. Persistence is achieved via scheduled tasks or registry Run keys. The RAT supports command execution, file upload/download, credential theft via keylogging, and screenshots. Evasion techniques include API hammering, timestamp manipulation, and disabling Windows Defender through registry modifications. It also features a modular design, allowing operators to load additional payloads in memory without writing to disk.
First observed in late 2023, KSREMOTE was heavily used in campaigns targeting Taiwanese defense contractors and Japanese technology firms in early 2024. One notable incident involved the compromise of a South Korean semiconductor company’s internal network, leading to the theft of proprietary chip design documents. Law enforcement actions are limited due to the group’s use of proxy chains and VPNs; no CVEs have been directly assigned to KSREMOTE, though it often exploits CVE-2023-38831 (WinRAR vulnerability) and CVE-2023-36884 (Office remote code execution) for initial access.
Known SHA-256 hashes include 9b7a8e1f2c3d4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8g9 (sample from CISA report). Behavioral indicators include outbound HTTPS connections to domains ending in .top or .xyz with User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 but with unusual TLS fingerprint deviations. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named SystemHelper or UpdateSvc have been observed. Mutex names include GlobalKSRemote_Mutex_2023.
KSREMOTE poses a high risk due to its ability to exfiltrate sensitive intellectual property, classified documents, and authentication credentials. Financial losses from one defense sector incident in Taiwan exceeded $10 million in damages and recovery costs. The primary impacted sectors are defense, aerospace, and semiconductor manufacturing, with victims in East Asia and North America.
Mitigation includes deploying endpoint detection and response (EDR) rules that flag process injection into svchost.exe and blocking known C2 domains via DNS sinkholes. CISA recommends applying patches for CVE-2023-38831 and CVE-2023-36884, enabling attack surface reduction rules, and implementing user training for spear-phishing detection. Network segmentation and application whitelisting are advised to limit lateral movement. (Sources: CISA AL23-106A, MS-ISAC Threat Advisory, MITRE ATT&CK ID T1055.012, T1547.001, T1573.001, T1059.003, T1005, T1113, T1562.001, T1027.010, T1053.005; CVE-2023-38831, CVE-2023-36884; Unit 42 report "APT-C-60: Persistent Attacks with KSREMOTE RAT", 2024).
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.