KaosRAT is a remote access trojan (RAT) identified in a joint FBI-led Cybersecurity Advisory as malware developed and used by the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau cyber group Andariel, also tracked as Onyx Sleet and formerly as PLUTONIUM, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. The advisory lists KaosRAT among Andariel-developed RATs and implants used in broader cyber espionage and ransomware operations. Across the group’s tooling, reported capabilities include arbitrary command execution, keylogging, screenshot capture, file and directory listing, browser history retrieval, process snooping, and uploading content to command-and-control infrastructure; the advisory states each implant typically has a designated C2 node to maintain access. KaosRAT is associated with campaigns in which Andariel commonly gains initial access by exploiting public-facing web servers using known vulnerabilities, including CVE-2021-44228 (Log4Shell), deploys web shells, establishes persistence via Scheduled Tasks, steals credentials with tools such as Mimikatz, and moves laterally using SMB and RDP. The group primarily targets defense, aerospace, nuclear, and engineering organizations for sensitive military and technical information, with additional targeting of medical and energy sectors, and has also funded espionage through ransomware operations against U.S. healthcare entities. The provided content does not include KaosRAT-specific indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ KaosRAT
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.