KRNRAT is a Windows kernel-mode rootkit and stealth backdoor used by Earth Kurma in cyberespionage operations against government and government-related telecommunications organizations in Southeast Asia, including the Philippines, Vietnam, Thailand, and Malaysia. It provides process manipulation, process protection and privilege elevation, file and directory hiding, network traffic concealment, shellcode execution, and command-and-control communication. Its implementation incorporates code from five open-source projects: ishellcode, Blackbone, Cronos-Rootkit, hidden, and venom-rootkit.
KRNRAT injects a memory-resident user-mode backdoor into a Windows service host process. The backdoor uses rootkit IOCTL interfaces to conceal its process and network connections and acts as a stager that retrieves a follow-on payload identified as SManager. Its configuration supports sleep intervals and scheduling by hour and day of the week. Earth Kurma deploys KRNRAT on compromised systems using legitimate Windows setup components and an installation information file to establish persistent, concealed access. A KRNRAT-specific initial infection vector has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The other rootkit we found is called KRNRAT. It’s a full-featured backdoor with various capabilities, including process manipulation, file hiding, shellcode execution, traffic concealment, and C&C communication.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Memory-resident backdoor/RAT that injects into svchost.exe to maintain stealthy execution.
Kernel-level rootkit and associated memory-resident backdoor used by Earth Kurma. It supports process manipulation and protection, privilege elevation, file and directory hiding, network concealment, and shellcode injection. It injects its user-mode agent into svchost.exe; that agent retrieves subsequent payloads and uses rootkit controls to hide its process and connections. SManager was identified as its final downloaded payload.
Stealthy backdoor/rootkit with capabilities for process manipulation, file and traffic concealment, shellcode execution, and persistent C2 communication.
Rootkit used to maintain persistence and conceal activity; supports stealthy access and data exfiltration (including via memory injection and disguised cloud communications).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.