logo

Kimsuky__2023__Ahnlab_Kimsuky-Group-AutoIt-Malware-RftRAT-Amadey_12-08-2023.pdf

ID: e44c2314-925b-43d1-a81c-bb458a905b3b

STIX ID: report--e44c2314-925b-43d1-a81c-bb458a905b3b

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2023-12-11

Last Modified Date: 2023-12-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASEC (AhnLab) reports that the Kimsuky APT group has been using LNK-based spear-phishing to deploy remote-access malware (Amadey, RftRAT, xRAT) and infostealers in 2023, with recent variants ported to AutoIt and packed with VMP; the report details infection chains, persistence and UAC bypass techniques, DGA usage, IOCs (MD5s, C2 domains/IPs), and post-infection tooling such as keyloggers, browser credential stealers, and RDP-related malware.