EndRAT is a remote access trojan written in AutoIt, also referred to in the provided content as EndClient RAT and in some reporting as AutoItRAT. It has been associated with Konni APT campaigns, including the campaign dubbed Operation Poseidon. Reported delivery chains used spear-phishing lures themed around North Korean human-rights organizations and South Korean financial institutions, as well as ZIP archives containing malicious LNK files. In observed infections, an AutoIt script disguised as a PDF or a compiled AutoIt payload masquerading as a PDF was executed, after which EndRAT was loaded and executed directly in memory. One reported chain used PowerShell to decode a decoy PDF from an LNK, download AutoIt3.exe and a disguised payload named APDNHFU.pdf from drfeysal[.]com into C:\Users\Public\Videos, and create a scheduled task named APDNHFU for persistence.
Capabilities directly described in the content include host information collection and exfiltration of sensitive information, with system data sent to C2 in JSON format. EndRAT supports file listing, file upload, file download, and interactive remote shell or command execution. One sample created the mutex Global\B073W15Z-D8QD-87B1-7465-CE77A8819E701 to prevent duplicate execution. Reported command support included cmd, exit, download, upload, listdir, delete, and run. Communications used a custom socket protocol rather than real HTTP, including use over port 80 with delimiters such as endServer9688 and endClient9688; related identifiers endServerFile9688 and endClientFile9688 were also reported. Another sample was described as hardcoding C2 157.180.88[.]26 on port 443.
The malware was observed in campaigns targeting victims in South Korea, with broader Konni reporting also tying related activity to targeting in Japan, Australia, and India. In the described Konni intrusions, operators used EndRAT for long-term access and collection of internal documents, account information, and system environment data, and in one campaign abused victims' KakaoTalk PC sessions for secondary propagation. Persistence mechanisms mentioned alongside EndRAT activity included scheduled tasks and startup-folder entries. Additional artifacts reported in connection with EndRAT include the disguised AutoIt payload APDNHFU.pdf containing the AU3!EA06 signature at offset 0x2720, startup execution via C:\ProgramData\NuGetPacks\AutoIt3.exe with mmlib.au3, and embedded developer build paths such as D:\3_Attack Weapon\Autoit\Build_Poseidon - Manage\client3.3.14.a3x and D:\3_Attack Weapon\Autoit\Build_ Poseidon - Attack\client3.3.14.a3x.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This script runs without requiring further user interaction and functions by loading and executing EndRAT-variant remote access trojans directly into memory.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
Malicious files were delivered through the KakaoTalk messenger, leveraging impersonation of acquaintances to conduct trust-based attacks... the attacker accessed the victim’s logged-in KakaoTalk PC version and used it as a channel to distribute malicious files.
it creates a scheduled task set to run every minute to continuously execute the malicious AutoIt script.
Following the initial infection, the threat actor established persistence by registering scheduled tasks...
The AutoIt script 'IoKlTr.au3,' which is run periodically by Task Scheduler, is a core component designed to perform persistent malicious activity on the system.
Specifically, after LNK execution, the platform detects cases where the actually invoked processes transition not to legitimate document viewers but to cmd.exe, powershell.exe, or AutoIt executables.
it creates a scheduled task set to run every minute to continuously execute the malicious AutoIt script.
Following the initial infection, the threat actor established persistence by registering scheduled tasks...
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
it creates a scheduled task set to run every minute to continuously execute the malicious AutoIt script.
Following the initial infection, the threat actor established persistence by registering scheduled tasks...
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
The threat actor concealed various malware components by encoding or encrypting them within AutoIt scripts... this script performs HMAC-based hash derivation to generate an AES decryption key and uses that key to decrypt an AES-encrypted payload.
The actor then remained concealed on the infected system for an extended period while collecting internal documents, user account information, and system environment data.
The actor then remained concealed on the infected system for an extended period while collecting internal documents, user account information, and system environment data.
One of EndRAT’s defining characteristics is that it uses a custom socket protocol over HTTP port 80 without actually using the HTTP protocol itself.
its command-and-control (C2) connection is made through a Germany-based domain. The domain is built on WordPress... multiple C2 servers were hosted on WordPress.
Evidence indicates that this threat actor continuously compromises poorly managed WordPress-based websites to use them as malware distribution points and C2 infrastructure.
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via spear-phishing. Delivered in ZIP archives from WordPress sites using an LNK that executes an AutoIt script disguised as a PDF; used for remote access and likely follow-on activity.
Remote access trojan delivered via an AutoIt script disguised as a PDF in a spearphishing campaign; used alongside compromised websites for distribution/C2.
Remote access trojan used in the Operation Poseidon campaign attributed to the Konni APT group; delivered via phishing lures and ZIP archives and hosted on compromised WordPress infrastructure after ad-platform open-redirect click tracking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.