KimJongRAT is a long-running Windows malware family associated with the North Korea-linked espionage actor Kimsuky. Active since at least the 2010s, it has evolved from a credential- and information-stealing tool into a modular intrusion set that can combine stealer, keylogging, clipboard capture, persistence, and remote-access functionality. Campaigns using KimJongRAT have primarily targeted South Korean users and organizations, often through socially engineered lures themed as public-sector notices, tax documents, or other trusted content, and have also aligned with broader Kimsuky espionage and financially motivated collection priorities, including cryptocurrency-related data theft.
Recent KimJongRAT activity has used multi-stage PE and PowerShell execution chains selected according to host security conditions such as Windows Defender status. Delivery commonly relies on spearphishing emails carrying malicious shortcut or document files that invoke script-based stages, including HTA, VBScript, and PowerShell components, while abusing legitimate cloud and developer platforms for staging and payload hosting. The malware performs anti-analysis checks, uses obfuscation and encrypted payload retrieval, and can establish persistence through user-run registry entries or equivalent startup mechanisms.
KimJongRAT’s core function is data theft. Documented variants collect system profiling data, process and software inventories, browser credentials, cookies, browser encryption material including Chromium master keys, email and mail-account artifacts, recent files, clipboard contents, keystrokes, and files of interest. Multiple variants also target messaging and collaboration artifacts such as Telegram and Discord, public-key certificate stores used in Korean environments, and cryptocurrency wallet data, including browser extension artifacts associated with numerous wallet platforms. Some variants package stolen data for later upload, while others rely on companion malware or later stages for exfiltration.
The family has also shown post-compromise expansion beyond pure stealing. Certain variants support command execution, file transfer, directory listing, malware updates, and installation of remote-management software or MeshCentral-based agents to secure ongoing access. Earlier reporting also showed KimJongRAT being delivered alongside other Kimsuky tooling such as BabyShark and PCRat, where it served primarily as a password extraction and information-stealing component within a broader intrusion workflow.
KimJongRAT is best characterized as a modular infostealer used in Kimsuky operations, with some variants incorporating backdoor-like remote access features. Its continued development, adaptive payload selection, abuse of legitimate services, and expanding collection scope reflect sustained operator investment in espionage-oriented credential theft and victim surveillance on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BabyShark Malware Part Two: Attacks Continue Using KimJongRat and PCRat
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky ... Malware families such as Kimsuky RAT, KimJongRAT, KONNI, and BabyShark have been linked to NICKEL KIMBALL activity.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
"The threat actors conduct extensive spearphishing operations, using typosquatting or domains thematically aligned with their target."
The obfuscated VBScript script invokes a Base64-encoded PowerShell script using the powershell -e option.
After opening "password.txt", the script runs the command "cmd /c sc query WinDefend"
Executing "password.txt.lnk" runs a command encoded in Base64... The obfuscated VBScript script invokes a Base64-encoded PowerShell script
The malware then downloads "app64.log" and "net64.log" in sequence, injecting each into chrome.exe and into itself, respectively.
After "sys.dll" starts, anti-VM checks run; if any condition is met, the malware deletes itself and terminates
Based on the service state, the flow branches to download and AES-decrypt either "v3.log" or "pipe.log"... The file "1.ps1" Base64-decodes the file specified via the FileName argument and executes the decoded content.
The malware enumerates the full process list, then filters out processes owned by the SYSTEM account
During system information collection, the malware queries the Windows version... Finally, the GetCPUInfo function issues the cpuid instruction to collect the CPU name.
The file "netlist.log" contains a list of file extensions and file system information collected via hard-coded cmd commands. The commands traverse drives, enumerate files matching specific extensions or keywords.
The malware queries registry values for each mail client type to collect account and profile information.
It then extracts the encrypted master key from each browser’s Local State file... Browser Credential and Cookie Collection
For C&C communications, the malware uses specific endpoints... Requests are formatted as "[C&C domain]/[victim_id]/[endpoint]"
The attacker abused GitHub to distribute malware... Upon execution, "pw.hta" downloads "password.txt" from Google Drive
For file uploads, the malware XORs the entire file with 0xFE... As an exception, the "netkey" file is sent via a regular POST
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A long-running DPRK-linked modular malware family attributed in the report to Kimsuky. It is delivered via phishing and uses PE and PowerShell branches to steal browser data, credentials, cookies, system and process information, mail client data, cryptocurrency wallet artifacts, Telegram/Discord/Exodus data, and to perform persistence, keylogging, clipboard capture, file collection, C2 tasking, and remote command execution. Recent variants also include a Chrome App-Bound Encryption master-key extraction component.
A named remote access trojan discussed as continuing to evolve, with the post indicating use of LOTS techniques/tools.
The content references a KimjongRAT variant described as expanding from information theft to securing remote access, indicating credential/data theft capabilities and remote access trojan functionality.
An updated KimjongRAT variant disguised as a tax notice. It retains information-stealing capabilities, expands collection targets to Telegram and Discord, and in the final stage installs a MeshCentral-based agent to obtain remote access and persistence-like control over the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.