logo

Technical Analysis of kkRAT

ID: 4967cea0-fe7e-5e53-afb6-3ce70292d93c

STIX ID: report--4967cea0-fe7e-5e53-afb6-3ce70292d93c

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-09-10

Date Updated: 2026-05-01

...
...

ThreatLabz describes a multi-stage malware campaign (observed May 2025) that uses GitHub Pages phishing sites and ZIP installers to deliver multiple RATs (ValleyRAT, FatalRAT, and a newly documented kkRAT). The report details sandbox/VM detection, dynamic API resolution, multi-stage shellcode loaders, AV/EDR disabling via vulnerable drivers and callback removal, persistence mechanisms, configuration and network protocol of kkRAT, available plugins/exports, and numerous IoCs and decryption tools to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.