HiKit, also known as Matrix RAT and Gaolmay, is a Windows rootkit with remote-access and backdoor capabilities used by Axiom, also tracked as Group 72. It supports remote shell access, arbitrary command execution, file transfers and exfiltration, peer connections, and proxying through compromised systems. Axiom has used HiKit within an espionage toolset targeting organizations with valuable intellectual property in manufacturing, industrial, aerospace, defense, and media sectors, particularly in the United States, Japan, Taiwan, and Korea.
HiKit installs a kernel driver as a virtual network adapter between the physical network interface and overlying protocol drivers. This position allows it to intercept incoming command-and-control packets and pass commands to user-mode threads for processing. Its passive, inbound command-and-control design can blend with legitimate HTTP traffic on compromised web servers; observed deployments included Windows servers in perimeter networks. HiKit also uses XOR encryption and DLL-loading abuse for persistence.
During installation, HiKit adds an attacker-generated certificate masquerading as a legitimate certificate to local machine trust stores and attempts to weaken driver-signature verification to facilitate driver loading. Its open-proxy functionality has enabled Remote Desktop tunneling and lateral movement using previously compromised credentials. Attackers have also used multi-homed infected systems as relay points between internal and external network segments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Axiom Derusbi 9002 RAT BLACKCOFFEE Derusbi Ghost RAT HiKit PlugX ZXShell APT17
"...a fileless version of the well-known ‘HiKit’ malware dubbed ‘Hias’."
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
Many entries describe XOR, XOR/ADD, bitwise NOT and XOR, ROR plus XOR, hexadecimal encoding after encryption, and custom encoding/obfuscation of HTTP traffic or beacons.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
4H RAT has the capability to create a remote shell. AuditCred can open a reverse shell on the system to execute commands. PlugX allows actors to spawn a reverse shell on a victim. QuasarRAT can launch a remote shell to execute commands on the victim’s machine.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Minor Software changes: ... Hikit
Backdoor that uses XOR encryption.
Backdoor/tool listed in MITRE ATT&CK Axiom reporting.
Well-known RAT family; content discusses a fileless variant (Hias) and newly discovered persistence mechanism.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.