EndClient RAT is an AutoIT-based Windows remote access trojan associated with Kimsuky-linked operations targeting the North Korean human rights community. It was used in a socially engineered campaign in which attackers leveraged trust relationships and one-to-one messaging through a compromised KakaoTalk account to persuade victims to open a malicious MSI installer. Reporting tied the activity to attacks against North Korean human rights defenders and identified dozens of downstream victims beyond the initial compromise.
The malware is delivered through a signed MSI package masquerading as legitimate software and accompanied by decoy components intended to reduce suspicion. Its installation chain drops and launches an obfuscated AutoIT payload, establishes persistence through both a scheduled task and a startup shortcut, and includes logic to avoid duplicate execution through a mutex check. EndClient RAT also incorporates defense-evasion behavior, including mutation of dropped components when Avast antivirus is detected and use of a code-signed installer to improve apparent legitimacy and reduce user-facing security warnings.
Once active, EndClient RAT initializes Windows networking and COM components, beacons host information to command-and-control infrastructure, and supports interactive post-compromise control. Documented capabilities include remote shell access through a hidden command interpreter and named-pipe-based interaction, as well as file upload and download. The malware therefore enables sustained access, remote command execution, and data movement on infected systems. Tradecraft observed in the campaign, including AutoIT usage, social engineering against civil society targets, and operational patterns, has been assessed as consistent with Kimsuky.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Latest posts New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack was first noticed on the remote wiping of the victims mobile phone in whereby the Threat Actor (TA) used the "Find, secure or erase a lost Android device" feature after compromising the Google account. Concurrently, the TA used her KakaoTalk account to further distribute the AutoIT based RAT
The BAT dropper sets up persistence via a scheduled task, then self-cleans. It drops the AutoIt payloads into Public\Music, registers a task “IoKlTr” that executes it every minute
This report details my technical reverse engineering of the novel Remote Access Trojan (RAT)... the AutoIT based RAT... Kimsuky have a habit of AutoIT payloads.
starts by creating a BAT script which copies the AutoIt3.exe binary and the Au3 script... The BAT dropper sets up persistence via a scheduled task, then self-cleans.
The BAT dropper sets up persistence via a scheduled task, then self-cleans. It drops the AutoIt payloads into Public\Music, registers a task “IoKlTr” that executes it every minute
The attack was first noticed on the remote wiping of the victims mobile phone in whereby the Threat Actor (TA) used the "Find, secure or erase a lost Android device" feature after compromising the Google account. Concurrently, the TA used her KakaoTalk account to further distribute the AutoIT based RAT
The BAT dropper sets up persistence via a scheduled task, then self-cleans. It drops the AutoIt payloads into Public\Music, registers a task “IoKlTr” that executes it every minute
The attack was first noticed on the remote wiping of the victims mobile phone in whereby the Threat Actor (TA) used the "Find, secure or erase a lost Android device" feature after compromising the Google account. Concurrently, the TA used her KakaoTalk account to further distribute the AutoIT based RAT
The AutoIt payloads into Public\Music... the Au3 script which is heavily obfuscated... you'll need to pull it from the memory of the AutoIT executable if you want it de-obfuscated.
The script would pop up and display an error dialog stating the app can’t run due to a language-pack mismatch and asks the user to install Korean. This of course, is not true.
The BAT dropper sets up persistence via a scheduled task, then self-cleans... then removes traces of the installer.
The attack was first noticed on the remote wiping of the victims mobile phone in whereby the Threat Actor (TA) used the "Find, secure or erase a lost Android device" feature after compromising the Google account. Concurrently, the TA used her KakaoTalk account to further distribute the AutoIT based RAT
This RAT was delivered via an Microsoft Installer package (MSI) titled "StressClear.msi"... Notably, the MSI that is used to deliver the RAT was code signed by Chengdu Huifenghe Science and Technology Co Ltd... the signature allowed it to look legitimate against AVs and not initiate any smart screen alerts by Windows.
The initiation phase of the malware checks if the global mutex identifier: Global\AB732E15-D8DD-87A1-7464-CE6698819E701 If it's present, another instance is running so it will exit. If not, it will create the mutex and continue. Next the ware checks for Avast antivirus
Once the C2 connection is established, it begins sending it's first system information beacon containing the computer name, OS version, username and IP.
The initiation phase of the malware checks if the global mutex identifier: Global\AB732E15-D8DD-87A1-7464-CE6698819E701 If it's present, another instance is running so it will exit. If not, it will create the mutex and continue. Next the ware checks for Avast antivirus
LZMADECOMPRESS - Decompress LZMA-compressed data... Most notably, the function is stored LZMA-commpressed and base64-encoded, so it must first be decoded and then decompressed
This sample, then connected to the C2 IP 116[.]202[.]99[.]218:443 via a TCP socket... Once the C2 connection is established, it begins sending it's first system information beacon
Further capabilities in the C2 mechanism allow the TA to download and upload files as detailed above, but check the file size is < 30mb.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EndClient RAT is a remote access trojan written in AutoIT, used by the Kimsuky group for espionage and persistent access.
EndClient RAT is a remote access trojan that enables remote shell command execution, system data gathering, file transfers, and persistence. It features anti-analysis capabilities, including polymorphic file mutations to evade detection, and is distributed via a spoofed Microsoft Installer package.
An AutoIT-based remote access trojan delivered via a signed MSI named 'StressClear.msi'. It establishes persistence via a scheduled task and startup LNK, uses a mutex to prevent duplicate execution, performs Avast-aware polymorphic mutation, connects to C2 at 116.202.99.218:443 over TCP, sends system information beacons, supports remote shell via named pipes and hidden cmd.exe, and can upload/download files using sentinel-framed JSON/file markers such as 'endClient9688' and 'endServer9688'.
Latest posts New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.