KRNRAT is a Windows kernel-mode rootkit and stealth backdoor associated with the Earth Kurma cyberespionage activity targeting government and telecommunications organizations in Southeast Asia. It combines components from multiple open-source projects to manipulate processes, hide files, execute shellcode, conceal network traffic, and maintain command-and-control communications. KRNRAT deploys a user-mode agent into a Windows service-host process, enabling memory-resident backdoor functionality and retrieval of follow-on payloads. Earth Kurma used KRNRAT alongside the MORIYA rootkit to establish persistent access and evade endpoint detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The KRNRAT rootkit manipulates processes, hides files, executes shellcode, conceals traffic and maintains command-and-control communication.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Memory-resident backdoor/RAT that injects into svchost.exe to maintain stealthy execution.
Stealthy backdoor/rootkit with capabilities for process manipulation, file and traffic concealment, shellcode execution, and persistent C2 communication.
Rootkit used to maintain persistence and conceal activity; supports stealthy access and data exfiltration (including via memory injection and disguised cloud communications).
Kernel-level rootkit used for stealth and persistence; supports process manipulation, file hiding, shellcode execution, traffic concealment, and C2. Loads a user-mode agent and injects it into svchost.exe to act as a backdoor and retrieve follow-on payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.