RftRAT is a Windows remote-access malware family used in North Korea-linked intrusion activity, including campaigns attributed to Kimsuky and Konni. It is commonly described as a backdoor or RAT that receives commands from command-and-control infrastructure and executes them on compromised hosts. Observed campaigns have primarily targeted South Korean individuals and organizations, including defense-related, government, media, academic, and North Korea-focused communities, often as part of espionage operations.
RftRAT has been delivered through spearphishing-driven infection chains that use malicious shortcut files, archive attachments, signed MSI installers, and AutoIt-based loaders. In multiple observed cases, attackers used lure documents or decoy content to induce execution, then unpacked or downloaded AutoIt components that installed or injected RftRAT. The malware has been observed injected into legitimate Windows processes, including through AutoIt-based injector stages, and some samples were packed or otherwise obfuscated to hinder analysis and evade detection.
Documented capabilities include remote command execution, file upload and download, process enumeration and termination, directory creation, file deletion and renaming, and reverse shell access. In Kimsuky-linked reporting, RftRAT was also observed using a UAC bypass via CMSTPLUACOM and ICMLuaUtil to obtain elevated execution. Its role in broader operations has included maintaining remote access, supporting follow-on reconnaissance and data theft, and enabling operators to manage compromised systems over extended periods.
RftRAT has appeared alongside other malware families such as Amadey, RemcosRAT, QuasarRAT, and EndRAT in multi-stage campaigns. In Konni operations, it was part of AutoIt-heavy toolchains that established persistence through scheduled tasks and startup mechanisms, while in Kimsuky activity it was associated with script-based loaders and post-compromise deployment of additional credential theft and surveillance tooling. Overall, RftRAT is best characterized as a Windows RAT/backdoor used in targeted espionage campaigns for persistent remote control and post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RftRAT is a backdoor that can receive commands from the C&C server and execute them.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process... Amadey... goes through svchost.exe before being injected into the iexplore.exe process and run.
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
While these malware are all packed with VMP when in distribution, recently, Amadey and RftRAT variants created with AutoIt have been used... This method seems to be for the purpose of bypassing security products.
The delivered archive contained a malicious LNK shortcut file disguised with the icon of a legitimate document.
Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process... Amadey... goes through svchost.exe before being injected into the iexplore.exe process and run.
The actor then remained concealed on the infected system for an extended period while collecting internal documents, user account information, and system environment data.
The HTTP request structure for sending the system information collected from the infected system to the C&C server is identical to that of the typical Amadey... After being run as administrator, RftRAT collects basic information about the infected system and sends it to the C&C server.
its command-and-control (C2) connection is made through a Germany-based domain. The domain is built on WordPress... multiple C2 servers were hosted on WordPress.
There is also a script for maintaining persistence as well as a downloader that downloads and executes additional payloads from an external source... it supports the feature to download additional payloads in not only an exe format, but also dll, PowerShell, vbs, and js formats.
55 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT with command and control infrastructure based in Japan, used for remote access and control.
RftRAT is a remote access trojan used to provide attackers with control over compromised systems, enabling credential theft and further lateral movement.
Remote access trojan deployed alongside other RATs in the MSI/AutoIt chain; referenced as previously used by Kimsuky in 2023.
한국 대상 지속 공격에 활용되는 RAT로, 단순 산술 난독화로 C2를 숨기고 일본 소재 서버와 통신하며 AutoIt 스크립트에 은닉되어 실행됩니다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.