KRNRAT is a full-featured stealth backdoor/rootkit used by the Earth Kurma APT in cyberespionage operations targeting government and telecommunications organizations in Southeast Asia, including reported activity affecting the Philippines, Vietnam, Thailand, and Malaysia. Trend Micro assessed Earth Kurma activity dating back to at least November 2020, with public reporting uncovering campaign activity from June 2024. KRNRAT is described as an amalgamation of five open-source projects and provides capabilities including process manipulation, file hiding, shellcode execution or injection, traffic concealment, command-and-control communication, and backdoor access. It loads a user-mode agent and injects it into svchost.exe to maintain memory-resident execution; the injected agent can retrieve follow-on payloads from a C2 server. In the Earth Kurma intrusion chain, KRNRAT was used alongside loaders such as DUNLOADER, TESDAT, and DMLOADER, Cobalt Strike Beacons, the MORIYA rootkit, and other tooling for reconnaissance, lateral movement, credential theft, and exfiltration. Reporting states the attackers used living-off-the-land techniques, including syssetup.dll, to install rootkits. Earth Kurma used KRNRAT and MORIYA to evade detection and maintain persistence while exfiltrating data via cloud services such as Dropbox and OneDrive. No specific IOCs beyond the svchost.exe injection behavior are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...rootkits such as KRNRAT and Moriya... KRNRAT is an amalgamation of five different open-source projects with capabilities such as process manipulation, file hiding, shellcode execution, traffic concealment, and command-and-control (C2) communication.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Memory-resident backdoor/RAT that injects into svchost.exe to maintain stealthy execution.
Stealthy backdoor/rootkit with capabilities for process manipulation, file and traffic concealment, shellcode execution, and persistent C2 communication.
Rootkit used to maintain persistence and conceal activity; supports stealthy access and data exfiltration (including via memory injection and disguised cloud communications).
Kernel-level rootkit used for stealth and persistence; supports process manipulation, file hiding, shellcode execution, traffic concealment, and C2. Loads a user-mode agent and injects it into svchost.exe to act as a backdoor and retrieve follow-on payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.