NavRAT is a Windows remote access trojan associated with North Korean cyber activity, particularly clusters tracked under Kimsuky and, in some reporting, Group123 or Lazarus-linked operations. It has been observed in campaigns targeting Korean users and broader strategic victims, including delivery through malicious Hangul Word Processor documents that execute embedded shellcode, launch a suspended Internet Explorer process, inject code into it, and retrieve the final payload. NavRAT has also been linked through tooling and campaign overlap to operators tracked as TA406.
The malware provides interactive remote access and supports post-compromise surveillance and host discovery. Documented behaviors include enumerating running processes with tasklist, using cmd.exe for discovery activity, logging keystrokes, and writing collected output to temporary files for local staging. NavRAT establishes persistence through Windows Registry autorun entries so it executes after reboot. For defense evasion and execution, it injects or copies itself into a running Internet Explorer process and executes shellcode in memory.
NavRAT is notable for using the Naver email platform as a command-and-control channel via SMTP, reflecting tradecraft tailored to South Korean environments. Its observed targeting, delivery through HWP lures, and mail-based command channel align with long-running DPRK espionage operations focused on Korean users and policy-relevant targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2019, a suspected TA406 operator uploaded several files to VirusTotal (NavRAT, QuasarRAT and BabyShark downloader).
A report from TALOS [2] mentionned the domain name « mailacounts.com », found in a compilation path of a NavRAT sample. TALOS assesses with medium confidence that the campaign they observed and NavRAT are linked to Group123.
Cisco noted (and documented) a final payload classified as “NavRAT” delivered using a very similar mechanism and containing the same file name from the ESTsecurity report. If we were making an assessment, our best guess would be that we would expect the same (or similar) payload here.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
For malicious HWP files... there will be malicious JavaScript present. In this case, we’re instead interested in the contents of one of the streams, BIN0003.eps... Pasting these into a file will reveal a relatively simple EPS script.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
We can see a handful of API calls... Now we see our network traffic endpoint (a compromised website) and a series of API calls directly related to communicating with that location.
detailing a newly identified malicious Hangul Word Processor (HWP) document... If we do have a copy and use it to open the document, we’ll notice two key events: the document will spawn a copy of Internet Explorer, and the analysis environment will make a network call to a compromised Korean website.
it will launch a suspended copy of Internet Explorer... and then create a remote thread in that process to execute this code
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
it will launch a suspended copy of Internet Explorer, inject additional code into its memory (using more resolved API calls) and then create a remote thread in that process to execute this code
it will launch a suspended copy of Internet Explorer, inject additional code into its memory... and then create a remote thread in that process to execute this code
it will launch a suspended copy of Internet Explorer... and then create a remote thread in that process to execute this code
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Several malicious subdomains discovered seem to spoof email or cloud service providers, but a few of them appear to target specific organizations.
it will launch a suspended copy of Internet Explorer, inject additional code into its memory (using more resolved API calls) and then create a remote thread in that process to execute this code
it will launch a suspended copy of Internet Explorer, inject additional code into its memory... and then create a remote thread in that process to execute this code
immediately after the noop sled, the first routine begins decoding additional code... Debugging this second set of shellcode... will show a similar pattern: an initial decoding routine, following by the resolution of the API calls needed to carry out the next task
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The main purpose of these activities seems to be credentials gathering, thanks to spearphishing emails and phishing websites.
the document will spawn a copy of Internet Explorer, and the analysis environment will make a network call to a compromised Korean website... these are used to communicate with the endpoint
Now we see our network traffic endpoint (a compromised website) and a series of API calls directly related to communicating with that location... The next call is for the code to read the response from the server and execute it
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Kimsuky malware previously used with Naver Mail for command delivery, mentioned here as historical context supporting attribution of AlphaSeed to Kimsuky.
Remote access trojan that copies itself into Internet Explorer to evade detection.
Remote access trojan that persists by creating a Registry key for execution on reboot.
Remote access trojan that uses tasklist /v to check running processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.