GSRAT is an AutoIt-based remote access trojan (RAT) observed since at least February 2025 and attributed in the provided reporting to activity associated with the North Korea-linked threat actor Konni. The malware was described in connection with spear-phishing campaigns, including a May 2025 campaign targeting organizations associated with Japanese financial institutions and domestic financial-sector-related organizations. Reported infection chains used spear-phishing with LNK and ZIP files, and persistence was established via the Startup folder and scheduled tasks. The content directly associates GSRAT with Konni operations and financial-sector targeting in Japan. No specific indicators of compromise are provided in the source content beyond the malware name, delivery chain elements, and persistence mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...attacks leveraging “GSRAT,” an AutoIt-based RAT observed since February 2025 and attributed to activity associated with the North Korea-linked threat actor “Konni.”
9 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AutoIt-based RAT delivered via spear-phishing (LNK/ZIP chain) with persistence via Startup folder and scheduled tasks; provides remote shell, file operations, enumeration, and execution; observed variants include JSON comms and custom delimiters.
AutoIt-based RAT delivered via spearphishing using an LNK plus AutoIt script; associated with Konni activity targeting Japan-linked financial organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.