CRAT is a Windows remote-access malware family first observed in 2020 in campaigns targeting South Korean users. It has been associated with spearphishing attacks using malicious Hangul Word Processor documents exploiting CVE-2017-8291, as well as trojanized software distributed through Korean community sites. Reporting has linked CRAT activity to the Larva-26005 cluster and to Lazarus-like or broader North Korea-linked tradecraft, with some intrusions also involving early Xctdoor variants and Hansom ransomware.
CRAT functions as a backdoor or RAT with capabilities including system reconnaissance, command execution, file operations, payload download, and exfiltration of collected user data. It has been reported communicating over HTTP and, in some cases, operating alongside an injector component that places payloads into legitimate processes. Historical intrusions in South Korea showed CRAT deployed together with ransomware and credential-stealing tooling, indicating use in broader post-compromise operations rather than as a standalone implant.
Observed delivery chains include spearphishing lures and malicious documents that execute embedded shellcode to retrieve additional payloads from attacker-controlled infrastructure. CRAT infections have also been tied to fake or trojanized software packages. Persistence has been reported through shortcut-based mechanisms and RegSvr32-assisted execution using application-package-style installation paths intended to blend with legitimate Windows software structure. Shared installation patterns, obfuscation approaches, and operational overlap have been cited in analyses connecting historical CRAT activity with later Xctdoor campaigns targeting South Korea, particularly in financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
그리고 내부에는 다음과 같은 PDB 정보를 담고 있는데 ... 유사한 'Crat Client' 문자열이 유사하게 사용된 바 있습니다. G:\crat0\client\Build\Win32\DllRelease\zero_Win32.pdb
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The commands this backdoor receives from the C2 server are as follows... 0X10011 Command execution with the window visible (using ShellExecute) 0X10012 Command execution with the window hidden (using CreateProcess)
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware referenced as part of past attack cases connected to Xctdoor.
Remote access trojan referenced in connection with past attack cases linked to Xctdoor.
HTTP 기반 C2 통신을 사용하는 백도어로, 시스템 정보 수집, 파일 작업, 명령 실행, 추가 페이로드 다운로드, 사용자 파일 압축 및 탈취 기능을 지원한다. 정상 프로세스 인젝션과 RegSvr32 기반 지속성을 사용하며 Xctdoor 초기 버전 및 Hansom과 함께 관찰되었다.
Backdoor malware communicating over HTTP that collects system information, performs file operations, executes commands, downloads additional payloads, compresses and exfiltrates files, and maintains persistence via LNK/Run key mechanisms. It was used in earlier Korea-focused campaigns and linked to later Xctdoor activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.