Technical Analysis of kkRAT
ID: 4967cea0-fe7e-5e53-afb6-3ce70292d93c
STIX ID: report--4967cea0-fe7e-5e53-afb6-3ce70292d93c
Feed Name: Zscaler Security Research Blog
ThreatLabz describes a multi-stage malware campaign (observed May 2025) that uses GitHub Pages phishing sites and ZIP installers to deliver multiple RATs (ValleyRAT, FatalRAT, and a newly documented kkRAT). The report details sandbox/VM detection, dynamic API resolution, multi-stage shellcode loaders, AV/EDR disabling via vulnerable drivers and callback removal, persistence mechanisms, configuration and network protocol of kkRAT, available plugins/exports, and numerous IoCs and decryption tools to aid defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
