LilithRAT is an AutoIt-based remote access trojan used in targeted intrusion activity associated with the KONNI threat ecosystem, which has been linked in reporting to North Korean state-aligned operations including overlaps or associations with Kimsuky and APT37. It has been observed in campaigns targeting individuals in South Korea, particularly people connected to North Korean defector and human-rights communities.
LilithRAT provides remote access functionality and has been associated with keylogging and broader post-compromise surveillance. In observed campaigns, it appeared as part of a multi-stage Windows infection chain that used AutoIt components for execution, obfuscation, and persistence, including scheduled-task-based relaunch and startup-based re-execution after reboot. Some samples were described as modified LilithRAT variants and also classified as EndRAT, distinguished by an internal marker while retaining similarity to the original AutoIt-based family.
Delivery has been tied to spearphishing and trust-based social engineering. Operators used malicious archives and MSI installers disguised as benign software, as well as compromised KakaoTalk sessions to send malware to victims' contacts. LilithRAT has also been distributed alongside or in conjunction with other remote access tools such as RemcosRAT, QuasarRAT, and RftRAT, indicating its role in flexible, multi-payload intrusion sets.
The malware's operational use fits espionage-oriented campaigns focused on long-term access, reconnaissance, credential collection, and monitoring of victims. In the same broader operations, attackers also abused compromised accounts and legitimate device-management features to hinder detection and response, although those actions are attributable to the intrusion set rather than uniquely to LilithRAT itself. LilithRAT is best understood as an AutoIt-based RAT employed in targeted social-engineering-driven campaigns against Windows users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The target code is similar to the AutoIt-based LilithRAT but in a modified form that uses the "endClient9688" JSON marker, and its command-and-control (C2) connection is made through a Germany-based domain. For this reason, it is also classified as EndRAT.
The files distributed were malicious AutoIt scripts and modules that enable remote access and keylogging, as well as various RATs, including LilithRAT and RemcosRAT.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
it creates a scheduled task set to run every minute to continuously execute the malicious AutoIt script.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AutoIt-based remote access trojan used for surveillance and control of compromised systems.
LilithRAT is a remote access trojan used to gain unauthorized access and control over infected devices, as part of North Korean APT operations targeting South Korean Android users.
LilithRAT is a remote access trojan used to gain unauthorized access and control over infected devices, as part of North Korean APT operations targeting South Korean Android users.
Remote access trojan (RAT) used for remote control, keylogging, and data exfiltration on compromised devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.