logo

Exploring a New KimJongRAT Stealer Variant and Its PowerShell Implementation

ID: bcad3360-e53c-5d7c-96ca-601227b96f58

STIX ID: report--bcad3360-e53c-5d7c-96ca-601227b96f58

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-06-17

Date Updated: 2026-04-28

Author: Dominik Reichel

...
...

This report analyzes two recently observed KimJongRAT stealer variants (a PE-based and a PowerShell-based variant) that use malicious LNK/HTA stagers hosted on a legitimate CDN to deliver loaders, orchestrators, a stealer and a keylogger; both variants steal browser data (including numerous crypto-wallet extensions), system information, and exfiltrate data to attacker-controlled C2 servers, with detailed infection flows, reverse-engineered behaviors, commands, and extensive IOCs (hashes, CDN and C2 URLs) provided for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.