Kaolin RAT is a Windows remote access trojan associated with North Korean Lazarus activity, including operations linked to Citrine Sleet and related clusters. It has been used in targeted intrusions against sensitive sectors such as aerospace and cryptocurrency, and has been observed as an upstream component in attack chains that subsequently deploy the FudModule rootkit. Reported lures include fake job-themed social engineering, with prior campaigns using professional networking and email-based approaches.
Kaolin RAT establishes AES-encrypted command-and-control communications and supports interactive remote administration functions including file upload and download and process creation or modification. Its role in observed campaigns is consistent with post-compromise control and payload delivery, including delivery of later-stage tooling used for privilege escalation and kernel-level tampering. In particular, earlier FudModule v2.0 intrusions used Kaolin RAT before exploitation of CVE-2024-21338 to obtain kernel memory read/write access.
The malware is part of a broader Lazarus tradecraft pattern combining social engineering, tailored victim targeting, and multi-stage tooling for stealthy persistence and follow-on exploitation. High-confidence reporting supports its use as a RAT and loader-like delivery component within espionage- and financially motivated North Korean operations, especially those focused on cryptocurrency-related organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Previous versions of FudModule (v2.0) were delivered by Kaolin RAT, utilizing another zero-day exploit ( CVE-2024-21338 ) to gain read/write access to the kernel memory. | Previous versions of FudModule (v2.0) were delivered by Kaolin RAT, utilizing another zero-day exploit (CVE-2024-21338) to gain read/write access to the kernel memory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan described as the delivery mechanism for earlier FudModule v2.0 infections.
A remote access trojan (RAT) used to load the FudModule rootkit, providing attackers with remote control over compromised systems, including file transfer and process manipulation capabilities.
Remote access trojan (RAT) delivered via fake job lures, used by Lazarus group for espionage and persistent access. Exploits a vulnerability in Windows driver appid.sys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.