Exploring a New KimJongRAT Stealer Variant and Its PowerShell Implementation
ID: bcad3360-e53c-5d7c-96ca-601227b96f58
STIX ID: report--bcad3360-e53c-5d7c-96ca-601227b96f58
Feed Name: Palo Alto Networks Unit 42
This report analyzes two recently observed KimJongRAT stealer variants (a PE-based and a PowerShell-based variant) that use malicious LNK/HTA stagers hosted on a legitimate CDN to deliver loaders, orchestrators, a stealer and a keylogger; both variants steal browser data (including numerous crypto-wallet extensions), system information, and exfiltrate data to attacker-controlled C2 servers, with detailed infection flows, reverse-engineered behaviors, commands, and extensive IOCs (hashes, CDN and C2 URLs) provided for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
