[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Exploring a New KimJongRAT Stealer Variant and Its PowerShell Implementation

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 25 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Dominik Reichel](https://unit42.paloaltonetworks.com/author/dominik-reichel/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 17, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybercrime](https://unit42.paloaltonetworks.com/category/cybercrime/)
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)
  * [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/)
  * [Infostealer](https://unit42.paloaltonetworks.com/tag/infostealer/)
  * [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/kimjongrat-stealer-variant-powershell/?pdf=download&lg=en&_wpnonce=279fa6c5e6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/kimjongrat-stealer-variant-powershell/?pdf=print&lg=en&_wpnonce=279fa6c5e6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Exploring%20a%20New%20KimJongRAT%20Stealer%20Variant%20and%20Its%20PowerShell%20Implementation&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimjongrat-stealer-variant-powershell%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimjongrat-stealer-variant-powershell%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimjongrat-stealer-variant-powershell%2F&title=Exploring%20a%20New%20KimJongRAT%20Stealer%20Variant%20and%20Its%20PowerShell%20Implementation "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimjongrat-stealer-variant-powershell%2F&text=Exploring%20a%20New%20KimJongRAT%20Stealer%20Variant%20and%20Its%20PowerShell%20Implementation "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimjongrat-stealer-variant-powershell%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Exploring%20a%20New%20KimJongRAT%20Stealer%20Variant%20and%20Its%20PowerShell%20Implementation%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimjongrat-stealer-variant-powershell%2F "Share in Mastodon")

## Executive Summary

This article provides a comprehensive analysis of two new variants of the KimJongRAT stealer. We combine our new research findings with existing knowledge to provide a comprehensive resource for understanding and combating these new KimJongRAT variants.

The KimJongRAT stealer was first described in [2013 by the Malware.lu CERT \[PDF\]](https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf). [We documented another variant](https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/) of this family in 2019.

One of the new variants uses a Portable Executable (PE) file and the other uses a PowerShell implementation. The PE and PowerShell variants are both initiated by clicking a Windows shortcut (LNK) file that downloads a dropper file from an attacker-controlled content delivery network (CDN) account. The PE variant's dropper deploys a loader, a decoy PDF and a text file. The dropper in the PowerShell variant deploys a decoy PDF file along with a ZIP archive.

The loader downloads more malicious files, including the stealer component for KimJongRAT.

The PowerShell variant's dropper file deploys a decoy PDF file and a ZIP archive containing scripts that include the KimJongRAT PowerShell-based stealer and keylogger components.

Both variants are designed to gather and transfer victim information and browser data, including from crypto-wallet extensions, to the attacker's server. The PE variant also collects FTP and email client information.

The infection sequence uses a multi-file approach and a legitimate CDN service to mask its malicious activities.

Palo Alto Networks customers are better protected from the malware samples described in this article through [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire), [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering), [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) and [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration). [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) are designed to prevent the execution of known malicious malware, and also prevent the execution of unknown malware using Behavioral Threat Protection and machine learning based on the Local Analysis module.

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**PowerShell**](https://unit42.paloaltonetworks.com/tag/powershell/), **[Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/)** |
|----------------------------|------------------------------------------------------------------------------------------------------------------------------------------|

## New KimJongRAT PE Variant

This section details the new KimJongRAT variant that uses PE files as final payloads.

The initial file of the execution chain is an LNK file, but we do not yet know how attackers distribute these files. Figure 1 shows the execution flow of the most recent KimJongRAT variant.
![Diagram depicting a multistage cyber attack involving various malware components and processes like dropper, downloader, decoy, DLLs, and orchestrator, interacting with Command and Control servers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-597346-143320-1.png) Figure 1. Malware execution chain of the latest KimJongRAT PE variant ([icon](https://www.flaticon.com/packs/files-131) [sources](https://www.flaticon.com/packs/business-online-2)).

* \*\*Step 1:\*\*When double-clicked, the initial LNK file downloads an HTML Application (HTA) file from an attacker-controlled CDN account, saves it to disk and runs it as shown in Figure 1
* **Step 2:** The HTA file drops three embedded files sys.dll, sexoffender.pdf and user.txt to disk
  * Sexoffender.pdf is a decoy PDF file opened by the victim's default PDF reader
  * The HTA file executes the sys.dll loader
* **Step 3:** The loader uses two payload URL strings in the user.txt file to retrieve two more files named main64.log and net64.log
  * These LOG files are a new KimJongRAT stealer component and an orchestrator
* \*\*Step 4:\*\*The orchestrator sends the collected information and data to a command and control (C2) server and awaits commands from the attackers

To more fully understand these steps, let's examine the associated files.

### **PE Variant Initial LNK File**

When double-clicking [one of the initial LNK files](https://www.virustotal.com/gui/file/3b0a3bd5b790e5f130e7819550613b7e0194a3475f553285a1b7dc18ecca9d02), the file uses the Windows tool cmd.exe to change the current directory to the Windows %temp% folder (shown in the Local base path and Command line arguments in Figure 2) . It then uses the Windows tool curl.exe to download an HTA file named pdf.hta from a legitimate CDN provider at cdn.glitch\[.\]global into the %temp% directory. The attacker abuses this service to host the next and subsequent stages of the malware.

The URL for the HTA file contains a parameter v with the string 1740535190239. This string is an [epoch date](<https://en.wikipedia.org/wiki/Epoch_(computing)>) that translates to Wednesday, February 26, 2025, 1:59 a.m. (GMT).

Finally, the LNK runs the downloaded HTA file using the Windows tool mshta.exe as shown in Figure 2.
![Command prompt screen displaying file paths and system details, with highlighted sections around the local base path and command line arguments.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-601742-143320-2.png) Figure 2. Execution related LNK information as shown in [LnkParse3](https://github.com/Matmaus/LnkParse3).

[This LNK file](https://www.virustotal.com/gui/file/3b0a3bd5b790e5f130e7819550613b7e0194a3475f553285a1b7dc18ecca9d02) contains unique metadata that can be used to find additional samples. Figure 3 shows the drive serial number, Windows OS version and machine ID of the system where the LNK file was created. Additionally, there is a Korean language string 응용 프로그램 (translated: application program) in the extra data section.
![Screenshot of system information and specifications, including drive types, volume names, and other serialized property details. Three sections are highlighted in blue boxes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-604525-143320-3.png) Figure 3. Metadata from the LNK file as shown in [LnkParse3](https://github.com/Matmaus/LnkParse3).

### **PE Variant First Stage HTA File**

The LNK sample we analyzed downloaded and saved an HTA file named pdf.hta to the Windows %temp% directory. [This HTA file](https://www.virustotal.com/gui/file/9c9136fc8a279ce395997dd42c075e265c6daec14b13bbe4237a4178769d270e) contains obfuscated VBS code. Additionally, the HTA file has three embedded payloads appended after the code as Base64 text.

Figure 4 shows an excerpt of the HTA file with the obfuscated VBS code and the start of the Base64-encoded payloads.
![A screenshot of a computer screen displaying a script or programming code in an integrated development environment or text editor. The displayed code includes numerical data, strings, and various programming functions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-607416-143320-4.png) Figure 4. Excerpt of the pdf.hta file content as shown in [Visual Studio Code](https://code.visualstudio.com/).

Figure 5 shows the deobfuscated version of this HTA file with the truncated Base64-encoded payloads.
![Screenshot of a computer code script displayed in a text editor. Indicated by arrows from top to bottom: Start of Base64 string for second payload. Start of Base64 string for first payload. Start of Base64 string for third payload.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-610383-143320-5.png) Figure 5. Deobfuscated version of pdf.hta as shown in [Visual Studio Code](https://code.visualstudio.com/).

The Base64 string for the first payload starting with JVBERi0xL is decoded through the Windows tool certutil.exe and dropped as the decoy PDF file sexoffender.pdf into the Windows %temp% directory. It is then opened by the default application for PDF files.

The Base64 string starting with aHR0cHM6L for the second payload is decoded and dropped as user.txt to the %localappdata% folder.

The third Base64 string starting with TVqQAAMAAA is decoded and dropped as sys.dll, also to the %localappdata% folder. This HTA file then runs sys.dll using rundll32.exe using sys.dll's only exported function named s.

The dropped user.txt is a text file containing URLs to the same CDN sub-directory that hosts the malicious HTA file, as shown in Figure 6.
![Screen capture showing a Notepad window with two URLs listed, both pointing to LOG files.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-614672-143320-6.png) Figure 6. The content of user.txt as shown in Windows Notepad.

[The last dropped file](https://www.virustotal.com/gui/file/f4d9547269e0cd7a0df97e394f688e0eb00b31965abd5e6ad67d373a7dc58f3b) is named sys.dll, and it downloads the files from the URLs in user.txt and executes them.

### **Second Stage Loader sys.dll**

The second stage loader named sys.dll is a 64-bit DLL internally named baby.dll. It has a single exported function named s that contains all the malware's functionality.

When this function is called with rundll32.exe, it first checks whether the malware is running on a virtual machine or sandbox as shown in Figure 7. If that is the case, the loader deletes itself and quits. If not, it creates a mutex named co\_sys\_co and starts a sub-thread.
![A screenshot of a computer code editor displaying several lines of C++ programming code, involving functions for file handling and system registry access.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-617482-143320-7.png) Figure 7. Decompiled source code of exported function s from sys.dll as shown in [IDA Pro](https://hex-rays.com/ida-pro).

The sub-thread checks if any previously dropped payloads are present in the %localappdata%\\net directory. It uses this directory to store downloaded payloads from the attacker's CDN stager URL.

The sys.dll loader expects any files downloaded to this folder to be encrypted data binaries with the first 16 bytes being the [RC4](https://en.wikipedia.org/wiki/RC4) decryption key for the remaining bytes. When it finds a file in this folder, it decrypts, executes and finally deletes the file.

After creating the sub-thread, the malware reads the URLs from the %localappdata%\\user.txt file previously dropped by the HTA file. It appends the date and time in epoch format as ?v=*\[epoch time\]* to each URL string. Afterwards, it contacts the CDN service to download the RC4-encrypted file net64.log into the %localappdata%\\net folder to load it reflectively.

This net64.log file is the new KimJongRAT stealer component. It endlessly runs a loop that only exits if the file %localappdata%\\micro.log.zip is present. This file is created by net64.log and contains the victim's stolen information and data.

When micro.log.zip is detected, the sys.dll loader downloads the second RC4-encrypted file main64.log from the CDN server and stores it as notepad.log. As soon as notepad.log is written to %localappdata%\\net, the sub-thread reads, decrypts, executes and deletes it. This decrypted file is the main orchestrator that implements network, backdoor and information-stealing functionality.

### **Third Stage Orchestrator and Backdoor**

The downloaded payload main64.log is internally named NetworkService.dll and has a compilation timestamp of December 3, 2024, 7:36 a.m. UTC. Figure 8 shows its [PDB file path](https://learn.microsoft.com/en-us/visualstudio/debugger/debug-interface-access/querying-the-dot-pdb-file).
![Screenshot displaying a debug window focused on raw data properties, including a highlighted 'PDB FileName' field showing a path to a file.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-621056-143320-8.png) Figure 8. PDB file path of net64.log as shown in [EXE Explorer](https://www.mitec.cz/exe.html).

As noted in Figure 8, the software has a PDB file path that includes the string \\research\\Spyware\\Advanced\\Covaware. A 2019 article by ESTsecurity describes a campaign named [Operation Giant Baby](https://blog-alyac-co-kr.translate.goog/2223?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp) where attackers used malware with the same name in activity relating to our [BabyShark article](https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/) from the same year.

This main64.log file is the main orchestrator that handles output created by the other downloaded file net64.log. While main64.log is primarily responsible for the network communication and backdoor functionality, net64.log is responsible for stealing credentials from browser and email or FTP clients.

The main orchestrator has a single exported function named fool, which contains the majority of the malware's functionality. The DllMain entry point is only used for various initialization routines. These routines create multiple directories associated with the base C2 URL and file paths that the malware uses later.

As a unique victim ID, main64.log uses the volume serial number. If the volume serial number cannot be obtained, main64.log uses a combination of the computer and username for the victim ID. It encodes this alternative ID value as a Base64 string, as shown in Figure 9.
![Screenshot of computer code in an editor, highlighting functions and variables related to URL processing and unique ID generation. Sections of the code are annotated with comments. From top to bottom are: C2 URL. Unique ID. Alternative unique ID.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-623990-143320-9.png) Figure 9. Decompiled C2 base URL creation function from main64.log as shown in [IDA Pro](https://hex-rays.com/ida-pro).

However, this alternative ID is not used throughout the malware's code and thus seems to be leftover code from earlier versions of this malware. After establishing the unique ID, main64.log calls the exported function fool before finally writing the clipboard data into a file.

The exported function fool shown in Figure 10 starts four threads before infinitely looping through a sleep call.
![Screenshot of a computer code in an IDE, featuring functions related to thread management and keyboard logging. The top line has "fool" highlighted in yellow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-627062-143320-10.png) Figure 10. Decompiled C2 string creation function from main64.log as shown in [IDA Pro](https://hex-rays.com/ida-pro).

These threads are named as follows:

* main\_thread
* clipboard\_log\_to\_netkey\_file
* keylogger\_log\_window\_title\_and\_keys
* keylogger\_flush\_to\_netkey\_file

The first thread named main\_thread shown below in Figure 11 implements the network, backdoor and information stealing functionality. The other three threads are dedicated to recording keystrokes, window titles and clipboard information.
![A screenshot of a computer code in an integrated development environment, featuring a function named "main\_thread" highlighted in yellow that involves various operations such as loading modules, setting internet options, uploading files, and implementing a sleep command.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-630031-143320-11.png) Figure 11. Decompiled main\_thread from main64.log as shown in [IDA Pro](https://hex-rays.com/ida-pro).

The network communication is implemented in an infinite loop that uploads collected data and requests commands from the C2 server. This malware implements three methods to communicate with the C2 server. To upload data or files, it uses the [HTTP POST](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Methods/POST) method with multipart/form-data, which we will subsequently describe as HTTP POST multi, or application/x-www-form-urlencoded, which we will call HTTP POST app. To download data, the malware uses an [HTTP GET](https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Methods/GET) request.

Figure 12 shows the initial network capture where the stolen browser data and the system information are sent to the C2 server.
![Wireshark screenshot displaying HTTP headers and other network request details with portions of the text redacted. Some of the information is also truncated.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-633720-143320-12.png) Figure 12. Initial network communication with the C2 server as shown in [Wireshark](https://www.wireshark.org/).

At first, the file micro.log.zip from the %localappdata% directory is copied into the %temp% directory as micro.log.zip\_. This file is then uploaded to the C2 server with an HTTP POST multi request and the hard-coded boundary string ----------sdfaffi3457839sfhjkaskl. Before it is uploaded as a value of the key file0, the ZIP archive is XORed with the key 0xFE.

Additionally, two keys val and id with the values delete and the volume serial number are sent to the C2 server. The former is most likely a note that the original file micro.log.zip is deleted after its copy gets uploaded, while the latter is used to associate the ZIP archive to a specific victim.

The HTTP POST multi method is always used to send file data, as is the same schema described above:

* Key: val, value: delete
* Key: id, value: \<UniqueVictimID\>
* Key: file0, value: \<XORedFileData\> (XOR key is always 0xFE)

The HTTP POST app method is either used to send encrypted data or to send the server-side delete command (further described as HTTP POST app delete). This delete command is used on the server side to clear out the appropriate command or feature queue. The schema is as follows for data:

* Key: id, value: \<UniqueVictimID\>
* Key: nm, value: \<FeatureName\>
* Key: val, value: \<XORedFileData\> (XOR key is always 0xFE) or delete

Next, the malware sends an HTTP GET request to the C2 URL ending with the victim's unique directory, which it creates from the volume serial number and the filename history.log\_. If the file is not already on the C2 server, the malware performs the following activities:

* Collecting various system information
* Writing it into a file named history.log in the %appdata% directory
* Creating a copy of it in the %temp% directory named history.log
* Sending it to the C2 server using the HTTP POST multi method

It collects the following system information in history.log:

* Hostname
* IP address
* Computer name
* Windows user account name
* Disk drive information (available drives, volume names, file system names, drive types)
* Operating system (version and product name)
* System type (32-bit or 64-bit)
* Internet Explorer version
* Start menu items
* CPU information

The initial communication sends the victim's data to the C2 server, and any additional actions from the C2 server are based on that initial data. Table 1 shows other information that is periodically uploaded to the C2 server.

|-----------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------|----------------------------------------------------|---------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Collected User Data**                                                                                         | **Queried C2 URL**                                           | **HTTP Method (and feature)**                      | **Created Local Files**                                                                                       | **Comment**                                                                                                                                                                                      |
| Search for files and directories in all directories based on a list of hard-coded file extensions and wildcards | Check file URL: \<C2Domain\>/\<UniqueVictimID\>/netlist.log\_ | Check file URL: GET  Upload file: POST multi | File with information: %localappdata%\\netlist.log  Copy of file with information: %temp%\\netlist.log\_ | Search files with the extensions .hwp, .pdf, .doc, .docx, .xls, .xlsx, .zip, .rar .egg, .txt, .jpg, .png, .jpeg, .alz, .ldb, and files and directories with the wildcards \*wallet\* and UTC--\* |
| Upload keylogger and clipboard data                                                                             | Upload file data: \<C2Domain\>                               | Upload file data: POST app                         | File with information: %localappdata%\\netkey                                                                 | The uploaded data is XORed with 0xFE                                                                                                                                                             |

Table 1. List of collected user data that is periodically uploaded to the C2 server.

To receive instructions from the C2 server, the malware periodically sends HTTP requests through hard-coded URLs. Afterward, it deletes all files and data that it downloaded from the C2 server. Table 2 shows the implemented commands together with their URLs, HTTP methods and involved local files:

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Description**                                                                                                                                           | **Queried C2 URL**                                                                                             | **HTTP Methods**                                                                          | **Created Local Files**                                                                                                        | **Comments**                                                                                                                                                                                      |
| Upload a specific file to the C2 URL                                                                                                                              | Get specified file: \<C2Domain\>/\<UniqueVictimID\>/out  Upload file and delete queue: \<C2Domain\>      | Get specified file: GET  Upload file: POST multi Delete queue: POST app delete      | Copy of specified file: %temp%\\\<SpecifiedFile\>\<RandomNumber\>                                                              | The specified file is RC4-encrypted, and the uploaded file is XORed with 0xFE                                                                                                                     |
| Download a file into a specified directory                                                                                                                        | Get file data and specified directory: \<C2Domain\>/\<UniqueVictimID\>/in  Delete queue: \<C2Domain\>    | Get file data and specified directory: GET  Delete queue: POST app delete           | N/A                                                                                                                            | The downloaded file is RC4-encrypted                                                                                                                                                              |
| Download a file into the %localappdata%\\net directory                                                                                                            | Get specified file URL: \<C2Domain\>/\<UniqueVictimID\>/cok  Delete queue: \<C2Domain\>                  | Get specified file URL: GET  Delete queue: POST app delete                          | N/A                                                                                                                            | The downloaded file is RC4-encrypted                                                                                                                                                              |
| Download a file into %localappdata%\\notepad.tmp                                                                                                                  | Check file URL: \<C2Domain\>/\<UniqueVictimID\>/tmp64  Delete queue: \<C2Domain\>                        | Check file URL: GET  Delete queue: POST app delete                                  | Downloaded file: %localappdata%\\notepad.tmp                                                                                   | -                                                                                                                                                                                                 |
| Run a command-line command                                                                                                                                        | Get cmd-line command: \<C2Domain\>/\<UniqueVictimID\>/cmd  Delete queue: \<C2Domain\>                    | Get cmd-line command: GET  Delete queue: POST app delete                            | -                                                                                                                              | The command is RC4-encrypted, with the first 16 bytes being the key for the remaining bytes                                                                                                       |
| Search for files and directories in a specified directory based on a list of hard-coded file extensions and wildcards. Write information to a file and upload it. | Get specified directory: \<C2Domain\>/\<UniqueVictimID\>/dir  Upload file and delete queue: \<C2Domain\> | Get specified directory: GET  Upload file: POST multi Delete queue: POST app delete | File with information: %localappdata%\\list.log  Copy of file with information: %localappdata%\\list.log\<RandomNumber\> | Search files with the extensions .hwp, .pdf, .doc, .docx, .xls, .xlsx, .zip, .rar, .egg, .txt, .jpg, .png, .jpeg, .alz, .ldb, and files and directories with the wildcards \*wallet\* and UTC--\* |

Table 2. List of backdoor commands.

### **Third Stage KimJongRAT Stealer**

The other downloaded file net64.log is the main KimJongRAT stealer component. The decrypted file is internally named dwm.dll and has a compilation timestamp of December 15, 2024, 4:03 a.m. UTC. It has three exported functions init\_engine, main\_engine and stop\_engine. Only the first function contains all the functionality, while the latter two only redirect execution to the entry point DllMain, which is empty.

When init\_engine is executed, the malware first resolves a list of API functions using GetProcAddress(). All function strings are encoded by a simple substitution cipher where characters are changed to others according to a mapping table. The following Python script contains the reconstructed algorithm and can be used for decoding these strings:  
import argparse class KimJongRATTool: CHAR\_MAPPING = { '!': '-', '#': ')', '$': ';', '%': '+', '\&': '=', '(': ':', ')': '#', '\*': '_', '+': '%', ',': '/', '-': '!', '.': '?', '/': ',', ':': '(', ';': '$', '\<': '\]', '=': '\&', '\>': '^', '?': '.', '@': '}', '\[': '{', '\]': '\<', '^': '\>', '_': '\*', 'a': 'm', 'b': 'q', 'c': 'f', 'd': 'h', 'e': 'x', 'f': 'c', 'g': 'l', 'h': 'd', 'i': 'p', 'j': 's', 'k': 't', 'l': 'g', 'm': 'a', 'n': 'z', 'o': 'r', 'p': 'i', 'q': 'b', 'r': 'o', 's': 'j', 't': 'k', 'u': 'y', 'v': 'w', 'w': 'v', 'x': 'e', 'y': 'u', 'z': 'n', '{': '\[', '}': '@' } @staticmethod def map\_string(encoded\_string: str) -\> str: return ''.join(KimJongRATTool.CHAR\_MAPPING.get(c.lower(), c).upper() if c.isupper() else KimJongRATTool.CHAR\_MAPPING.get(c, c) for c in encoded\_string) def decode\_string(self, encoded\_string: str) -\> None: print(f'Decoded string: {self.map\_string(encoded\_string)}') def decode\_strings(self, file\_path: str) -\> None: with open(file\_path) as f: print('Decoded strings:') for line in f: print(self.map\_string(line.strip())) def main(): parser = argparse.ArgumentParser() group = parser.add\_mutually\_exclusive\_group(required=True) group.add\_argument('-f', '--file\_path', type=str, help='(Absolute) File path with encoded strings.') group.add\_argument('-s', '--encoded\_string', type=str, help='Encoded string.') args = parser.parse\_args() kjrt = KimJongRATTool() if args.file\_path: kjrt.decode\_strings(args.file\_path) else: kjrt.decode\_string(args.encoded\_string) if **name** == '**main**': main()

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 | import argparse class KimJongRATTool: CHAR\_MAPPING = { '!': '-', '#': ')', '$': ';', '%': '+', '\&': '=', '(': ':', ')': '#', '\*': '_', '+': '%', ',': '/', '-': '!', '.': '?', '/': ',', ':': '(', ';': '$', '\<': '\]', '=': '\&', '\>': '^', '?': '.', '@': '}', '\[': '{', '\]': '\<', '^': '\>', '_': '\*', 'a': 'm', 'b': 'q', 'c': 'f', 'd': 'h', 'e': 'x', 'f': 'c', 'g': 'l', 'h': 'd', 'i': 'p', 'j': 's', 'k': 't', 'l': 'g', 'm': 'a', 'n': 'z', 'o': 'r', 'p': 'i', 'q': 'b', 'r': 'o', 's': 'j', 't': 'k', 'u': 'y', 'v': 'w', 'w': 'v', 'x': 'e', 'y': 'u', 'z': 'n', '{': '\[', '}': '@' } @staticmethod def map\_string(encoded\_string: str) -\> str: return ''.join(KimJongRATTool.CHAR\_MAPPING.get(c.lower(), c).upper() if c.isupper() else KimJongRATTool.CHAR\_MAPPING.get(c, c) for c in encoded\_string) def decode\_string(self, encoded\_string: str) -\> None: print(f'Decoded string: {self.map\_string(encoded\_string)}') def decode\_strings(self, file\_path: str) -\> None: with open(file\_path) as f: print('Decoded strings:') for line in f: print(self.map\_string(line.strip())) def main(): parser = argparse.ArgumentParser() group = parser.add\_mutually\_exclusive\_group(required=True) group.add\_argument('-f', '--file\_path', type=str, help='(Absolute) File path with encoded strings.') group.add\_argument('-s', '--encoded\_string', type=str, help='Encoded string.') args = parser.parse\_args() kjrt = KimJongRATTool() if args.file\_path: kjrt.decode\_strings(args.file\_path) else: kjrt.decode\_string(args.encoded\_string) if **name** == '**main**': main() |

The same cipher is used to encode other sensitive strings related to the stealer's functionality.

Based on the list of decoded function strings, the stealer attempts to retrieve information from various popular browsers and FTP or email clients. Other sensitive strings related to the stealer functionality, like the browser extension ID, are encrypted by a simple XOR-based cipher.

The malware stores the stolen data in plain text and SQLite files in a directory %temp%\\*\[RandomName\]*.tmp. An overview of the victim information is stored in the file %temp%\\*\[RandomName\]*\\micro.log. This file contains the following information:

* Operating system information
* CPU information
* Process information
* Start menu programs
* Website/cookie/password information of supported browsers
* Configuration and password information of supported email clients
* Password information of supported FTP clients

The malware also searches all supported browsers for multiple cryptocurrency wallet extensions shown in Table 3.

|----------------------------------|--------------------|
| **Extension ID**                 | **Extension Name** |
| nkbihfbeogaeaoehlefnkodbefgpgknn | MetaMask           |
| egjidjbpglichdcondbcbdnbeeppgdph | Trust Wallet       |
| ibnejdfjmmkpcnlpebklmnkoeoihofec | TronLink           |
| aholpfdialjgjfhomihkjbmgjidlcdno | Exodus Web3 Wallet |
| fhbohimaelbohpjbbldcngcnapndodjp | BEW lite           |
| mcohilncbfahbmgdjkbpemcciiolgcge | OKX Wallet         |
| bfnaelmomeimhlpmgjnjophhpkkoljpa | Phantom            |
| ejbalbakoplchlghecdalmeeeajnimhm | MetaMask           |
| pbpjkcldjiffchgbbndmhojiacbgflha | OKX Wallet         |
| bhhhlbepdkbapadjdnnojkbgioiodbic | Solflare Wallet    |

Table 3. Searched for browser extensions with their corresponding IDs.

The extension IDs for each browser are stored in the file %temp%\\*\[RandomName\]*\\ext.log.

Additionally, the malware steals various SQLite database files for supported browsers found in each browser's user data directory. For example, for Google Chrome, these files can be found in C:\\Users\\*\[UserName\]*\\AppData\\Local\\Google\\Chrome\\User Data\\Default for the default user. These database files contain detailed information about the user from browser features including bookmarks, history, saved passwords and installed extensions. The malware searches for the following in the database files:

* Cookies
* Login data
* Web data

These files are copied to the %temp%\\*\[RandomName\]*.tmp directory and renamed by prepending the profile user and a browser indicator. The last file created in this directory contains the master encryption key derived from a browser's Local State file. This key is needed to decrypt sensitive browser data, such as stored passwords or cookies.

Finally, these files are compressed using the PowerShell Compress-Archive command to %localappdata%\\micro.log.zip. This file is then uploaded to the C2 server by the orchestrator.

## Previous KimJongRAT PE Variants

We have also discovered other variants of this malware execution chain, dating back to at least August 2024. The first variants deployed 32-bit DLL files as the final stealer and orchestrator payloads, which is different from the latest variant that uses 64-bit DLL files. Also, the execution chain sometimes differs in the way that the second-stage loader drops the decoy PDF, or whether it uses the decoy PDF at all.

Other differences are that the initial LNK file does not use cmd.exe and curl.exe but instead powershell.exe with the Invoke-WebRequest command to download the next stage HTA dropper.

## New KimJongRAT PowerShell Variant

This section discusses the latest variant of KimJongRAT, which uses a PowerShell information and crypto-wallet stealer as its final payload. It is very similar to the PE variant in its functionality but focuses on only stealing system and browser data.

This execution chain uses a variety of file types and is carried out in multiple stages. The initial file is an LNK file as seen in Figure 13, which illustrates the full execution chain.
![Flowchart detailing a multistage malware attack involving several components like Downloader, Dropper, Decoy, Runner, Stealer, and Keylogger, each linked by directional arrows indicating the sequence of actions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-636695-143320-13.png) Figure 13. Malware execution chain of the latest PowerShell variant ([icon](https://www.flaticon.com/packs/files-131) [sources](https://www.flaticon.com/packs/business-online-2)).

* **Step 1:** When double-clicked, the LNK file downloads an HTA file from an attacker-controlled CDN account to disk and runs it, as shown above in Figure 13
* \*\*Step 2:\*\*When executed, this HTA file drops an embedded decoy PDF and a ZIP archive to disk
* \*\*Step 3:\*\*The decoy file is opened by the default installed PDF reader, and then files from the ZIP archive are extracted and saved to disk
* \*\*Step 4:\*\*From those extracted files, a PowerShell file loads the stealer and keylogger and sets the runner VBS script for persistence
* \*\*Step 5:\*\*The stealer sends the collected information and data to the C2 server and awaits commands from the attackers

### **PowerShell Variant Initial LNK File**

[An example of an initial LNK file](https://www.virustotal.com/gui/file/a66c25b1f0dea6e06a4c9f8c5f6ebba0f6c21bd3b9cc326a56702db30418f189) (SHA256 hash: a66c25b1f0dea6e06a4c9f8c5f6ebba0f6c21bd3b9cc326a56702db30418f189) submitted to VirusTotal is named 성범죄자 신상정보 고지.pdf.lnk (translated from Korean: "Sex Offender Personal Information Notification"). This sample is almost identical to the sample we reviewed in the PE malware chain. The only difference is that it downloads a different HTA file named sfmw.hta and uses a different value for the parameter v as shown in Figure 14.
![Image showing a Windows command prompt with text displaying file path and system information for a program. Some of the information is highlighted in red boxes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-640269-143320-14.png) Figure 14. Execution related LNK data as shown in [LnkParse3](https://github.com/Matmaus/LnkParse3).

The LNK file's metadata is identical to the one described in the latest PE malware execution chain.

### **First Stage HTA File**

The [downloaded sfmw.hta file](https://www.virustotal.com/gui/file/02783530bbd8416ebc82ab1eb5bbe81d5d87731d24c6ff6a8e12139a5fe33cee) is dropped into the Windows %temp% directory. This file contains VBScript code, obfuscated with the same algorithm as the one in the PE variant. Unlike the PE variant, sfmw.hta only has two embedded payloads.

Figure 15 shows an excerpt of this HTA file with the obfuscated code and one of the two Base64-encoded payloads.
![Screenshot of a computer script written in VBScript, displayed in a text editor with numbered lines and syntax highlighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-643245-143320-15.png) Figure 15. Excerpt of the sfmw.hta file content as shown in [Visual Studio Code](https://code.visualstudio.com/).

Figure 16 shows the deobfuscated version of the HTA file with the truncated Base64-encoded payloads.
![A screenshot of a computer script written in VBScript displayed in a text editor with various commands for file manipulation and execution.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-646826-143320-16.png) Figure 16. Deobfuscated version of sfmw.hta as shown in [Visual Studio Code](https://code.visualstudio.com/).

Figure 16 shows that the script within the HTA file uses findstr.exe with the /b parameter to locate each Base64-encoded payload within the file text. Then, the script uses certutil.exe to decode the Base64 strings.

At first, the embedded payload starting with the Base64-encoded data JVBERi0xLj is dropped as sexoffender.pdf (same filename as in the PE variant) into the Windows %temp% directory. This [decoy PDF file](https://www.virustotal.com/gui/file/455cea72b7cd2e2b6fc7bb09c946db03ea624f26fe32910e05a46a63d63e142c) is then opened by the default installed PDF reader and seems to be a Korean form related to sex offenders, as shown in Figure 17.
![Image of a formal document in Korean, featuring a structured layout with headings, bullet points, and multiple sections of text.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-649748-143320-17.png) Figure 17. PDF decoy document sexoffender.pdf as shown in [Adobe PDF Reader](https://www.adobe.com/acrobat/pdf-reader.html).

The second payload from the HTA file is a Base64-encoded string starting with UEsDBBQAAA. This string is decoded and dropped as [a ZIP archive](https://www.virustotal.com/gui/file/50a392f1aa8b88d0818c2d8716d195e999bf439564ec6a895dcde4a0463ece13) named pipe.zip to the %localappdata% folder. The files from this archive are extracted, and the PowerShell file named 1.ps1 is run. The other unpacked file named 1.log is passed as an argument to the PowerShell file.

Figure 18 shows that the pipe.zip archive contains four files.
![A screenshot displaying a file explorer window with a list of four files, along with details including file size, packed size, and timestamps for modified, created, and accessed dates. All files have an attribute set to 'A'.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-652766-143320-18.png) Figure 18. Files contained in pipe.zip as shown in [7-Zip](https://www.7-zip.org/).

Components of this malware were created in September 2024, as shown in the Modified, Created and Accessed dates of the files 1.ps1 and 1.vbs. The files 1.log and 2.log that contain the Base64-encoded PowerShell stealer were updated in March 2025.

Table 4 shows the names and SHA256 hashes of these files.

|--------------|------------------------------------------------------------------|
| **Filename** | **Hash**                                                         |
| 1.log        | ab8862628584aa429fe7614d1c674bbdf324fa2668c4d3c94670cf6b6db597f6 |
| 1.ps1        | 97d1bd607b4dc00c356dd873cd4ac309e98f2bb17ae9a6791fc0a88bc056195a |
| 1.vbs        | f73164bd4d2a475f79fb7d0806cfc3ddb510015f9161e7dce537d90956c11393 |
| 2.log        | 3589c871b56cf76ce28c6be914b206afe977ec13b0894f56e05c5772a3c7e495 |

Table 4. Files contained in pipe.zip.

### **Second Stage PowerShell Stealer**

The PowerShell file 1.ps1 shown in Figure 18 is a simple loader that decodes and runs the Base64-encoded file [1.log](https://www.virustotal.com/gui/file/b1f9b450b97320de54f2450ace151b4f16444dc871f5e89487d52d862ce13cc2) that is passed as an argument. It executes the PowerShell code with the Invoke-Expression alias iex as shown in Figure 19.
![Image of a code snippet in PowerShell using functions to convert a string from Base64 encoding.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-656337-143320-19.png) Figure 19. PowerShell code of 1.ps1 as shown in [Visual Studio Code](https://code.visualstudio.com/).

The decoded script in 1.log is a PowerShell stealer with backdoor functionality. This malware can be logically divided into three parts:

* Header
* Malware functionality
* Main function logic

The header defines several variables and performs a simple anti-VM check as shown in Figure 20.
![Screenshot displaying a PowerShell script snippet with conditional logic to check for VMware and delete specific log files from a computer system.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-659165-143320-20.png) Figure 20. Variable definitions and anti-VM check of the PowerShell stealer as shown in [Visual Studio Code](https://code.visualstudio.com/).

The header part creates a new directory in the Windows %temp% folder named after the system's UUID retrieved from the [WMI ComputerSystemProduct class](https://learn.microsoft.com/en-us/windows/win32/cimwin32prov/win32-computersystemproduct), and it defines a few path variables and the C2 URL. Additionally, this part checks whether the victim host is a VMware virtual machine based on the UUID serial number value. If it is a VMware system, the malware deletes itself and then exits. However, this anti-VM check is flawed, as the retrieved UUID does not contain any VM-related strings in comparison to other fields of the same WMI class.

The second part of the malware is its functionality. This part consists of multiple functions, shown in Figure 21.
![Screen of code with syntax highlighting showing functions named UploadFile, Unprotect-Data, GetExWFile and several more, with line numbers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-662082-143320-21.png) Figure 21. Folded functions of the PowerShell stealer as shown in [Visual Studio Code](https://code.visualstudio.com/).

Table 5 shows an overview of these functions.

|------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Function Name**      | **Description**                                                                                                                                                                                                                                                                                   |
| UploadFile             | Uploads a file from a specified path to a provided URL, appending "\&ap=1" to the URL after the first of each chunk. It also has an optional tag string parameter, which is used to create a unique filename along with a random number.                                                          |
| Unprotect-Data         | Takes a Base64-encoded encrypted string, decodes it and decrypts the resulting data using the current user's data protection scope. It then writes the decrypted data to a file at the specified path.                                                                                            |
| GetExWFile             | Explained in more detail below.                                                                                                                                                                                                                                                                   |
| GetBrowserData         | Explained in more detail below.                                                                                                                                                                                                                                                                   |
| Init                   | Collects comprehensive system information, including operating system, CPU, disk, volume, network adapter details, running processes and installed software. It then writes this information to a text file info.txt located at $tempPath\\$id.                                                   |
| DownloadFile           | Downloads a file from a specified URL and saves it to a specified file path.                                                                                                                                                                                                                      |
| CreateFileList         | Described in more detail below.                                                                                                                                                                                                                                                                   |
| RegisterTask           | Described in more detail below.                                                                                                                                                                                                                                                                   |
| Send                   | Compresses a specified directory into a ZIP archive, which it then renames to init.dat and constructs a URL by appending the BIOS ID to the C2 base URL. It then uploads the init.dat file to this URL and, if successful, deletes the contents of the specified directory and the init.dat file. |
| Get-ShortcutTargetPath | Retrieves the target path of a specified Windows shortcut by creating a COM object of WScript.Shell and using its CreateShortcut method.                                                                                                                                                          |
| RecentFiles            | Retrieves the target paths of all recent files (shortcuts) in the user's Windows account and appends them to a text file recent.txt.                                                                                                                                                              |
| Work                   | Described in more detail below.                                                                                                                                                                                                                                                                   |

Table 5. Overview of the PowerShell functions used in the stealer.

The GetBrowserData function is designed to extract various types of data from multiple browsers, including [Edge](https://www.microsoft.com/en-us/edge/), [Chrome](https://www.google.com/chrome/), [Naver Whale](https://whale.naver.com/en/) and [Firefox](https://www.mozilla.org/en-US/firefox/). This function uses another function named GetExWFile to manage specific data associated with cryptocurrency wallet browser extensions. Figure 22 shows an excerpt of the GetBrowserData function. This excerpt indicates the malware is still in development with many lines of code commented out.
![A screenshot of computer code with syntax highlighting, showing the function "GetBrowserData" with various coding elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-665250-143320-22.png) Figure 22. GetBrowserData function as shown in [Visual Studio Code](https://code.visualstudio.com/).

During the data extraction process, the GetBrowserData function uses three hash tables to map specific extension IDs to their corresponding names. Table 6 shows all hashes with their corresponding extensions.

|----------------------------------|-----------------------------|
| **Extension ID**                 | **Extension Name**          |
| nkbihfbeogaeaoehlefnkodbefgpgknn | MetaMask                    |
| egjidjbpglichdcondbcbdnbeeppgdph | Trust Wallet                |
| ibnejdfjmmkpcnlpebklmnkoeoihofec | TronLink                    |
| aholpfdialjgjfhomihkjbmgjidlcdno | Exodus Web3 Wallet          |
| fhbohimaelbohpjbbldcngcnapndodjp | BEW lite                    |
| mcohilncbfahbmgdjkbpemcciiolgcge | OKX Wallet                  |
| bfnaelmomeimhlpmgjnjophhpkkoljpa | Phantom                     |
| ejbalbakoplchlghecdalmeeeajnimhm | MetaMask                    |
| pbpjkcldjiffchgbbndmhojiacbgflha | OKX Wallet                  |
| opfgelmcmbiajamepnmloijbpoleiama | Rainbow                     |
| phkbamefinggmakgklpkljjmgibohnba | Pontem Crypto Wallet        |
| dmkamcknogkgcdfhhbddcghachkejeap | Keplr                       |
| nphplpgoakhhjchkkhmiggakijnkhfnd | TON Wallet                  |
| jbppfhkifinbpinekbahmdomhlaidhfm | iWallet Pro                 |
| aiifbnbfobpmeekipheeijimdpnlpgpp | Station Wallet              |
| bhhhlbepdkbapadjdnnojkbgioiodbic | Solflare Wallet             |
| jblndlipeogpafnldhgmapagcccfchpi | Kaika Wallet                |
| fpkhgmpbidmiogeglndfbkegfdlnajnf | Cosmostation Wallet         |
| onhogfjeacnfoofkfgppdlbmlmnplgbn | SubWallet                   |
| pdliaogehgdbhbnmkklieghmmjkpigpa | Bybit Wallet                |
| acmacodkjbdgmoleebolmdjonilkdbch | Rabby Wallet                |
| aflkmfhebedbjioipglgcbcmnbpgliof | Backpack                    |
| fnjhmkhhmkbjkkabndcnnogagogbneec | Ronin Wallet                |
| ppbibelpcjmhbdihakflkdcoccbgbkpo | UniSat Wallet               |
| anokgmphncpekkhclmingpimjmcooifb | Compass Wallet              |
| dlcobpjiigpikoobohmabehhmhfoodbb | Argent X Starknet Wallet    |
| efbglgofoippbgcjepnhiblaibcnclgk | Martian Aptos \& Sui Wallet |
| ejjladinnckdgjemekebdpeokbikhfci | Petra Aptos Wallet          |
| fcfcfllfndlomdhbehjjcoimbgofdncg | Leap Cosmos Wallet          |
| jnlgamecbpmbajjfhmmmlhejkemejdma | Braavos Starknet Wallet     |
| fijngjgcjhjmmpcmkeiomlglpeiijkld | Talisman Wallet             |
| mkpegjkblkkefacfnmkajcjmabijhclg | Magic Eden Wallet           |
| aeachknmefphepccionboohckonoeemg | Coin98 Wallet               |
| idnnbdplmphpflfnlkomgpfbpcgelopg | XVerse Wallet               |
| dmkamcknogkgcdfhhbddcghachkejeap | Keplr                       |
| nnpmfplkfogfpmcngplhnbdnnilmcdcg | Uniswap                     |
| bfnaelmomeimhlpmgjnjophhpkkoljpa | Phantom                     |
| opcgpfmipidbgpenhmajoajpbobppdil | Sui Wallet                  |
| hnfanknocfeofbddgcijnmhnfnkdnaad | Coinbase Wallet             |
| kkpllkodjeloidieedojogacfhpaihoh | Enkrypt                     |

Table 6. Searched for browser extensions with their corresponding IDs.

The GetExWFile function retrieves files associated with these extensions, based on the specific handling procedures defined for each of the hash tables. The function begins by attempting to retrieve the encrypted master key from the local user's data for each browser.

If the browser process is running, it halts the process to avoid file access conflicts. Then, it navigates through all user profiles for each browser within the User Data directory. For every user profile, it duplicates various data types, such as Login Data and Bookmarks, to a new location.

For Edge, Chrome and Naver Whale, the GetExWFile function processes data related to browser extensions. It receives the browser's name, the profile path and the profile name as arguments. After it duplicates the necessary data, the function enumerates all extensions installed for the user profile and appends this list to a text file named extensions.txt. If the browser process was initially running, this function restarts the process once it has copied all the data.

For Firefox, the function specifically copies certain files (key4.db, key3.db, cookies.sqlite, logins.json) associated with each user profile.

The CreateFileList function scans all file system drives on the system, specifically targeting the Users directory on the C:\\ drive. It searches for files with extensions shown in Table 7.

|--------------------------|-----------------------|
| **Extensions**           | **File Association**  |
| .doc, .docx, .xls, .xlsx | Microsoft Office      |
| .hwp, .hwpx              | Hancom Office         |
| .txt, .csv, .pdf, .log   | Text related          |
| .jpg, .jpeg, .png        | Images                |
| .rar, .zip, .alz         | Archives              |
| .ldb                     | Microsoft Access lock |
| .eml                     | Email                 |

Table 7. List of files with their extensions that the stealer is looking for.

Additionally, the CreateFileList function searches for any files matching the name patterns of various cryptocurrency-related terms and names as shown in Figure 23.
![Screenshot of a computer screen displaying a PowerShell script used for handling file management operations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-669052-143320-23.png) Figure 23. CreateFileList function as shown in [Visual Studio Code](https://code.visualstudio.com/).

All matching files are then written into a text file named FileList.txt.

The RegisterTask function shown in Figure 24 creates an entry in the Windows registry under HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run key for persistence. For this, it creates an entry named WindowsSecurityCheck and uses the file path to 1.vbs previously dropped from the ZIP archive.
![Screenshot of computer code using PowerShell functions, including commands such as "RegisterTask."](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-671989-143320-24.png) Figure 24. RegisterTask function as shown in [Visual Studio Code](https://code.visualstudio.com/).

A commented-out code line in 1.ps1 (see Figure 24, line 409) indicates it has run 1.log directly in the malware code at some point. This functionality has been outsourced to the external file 1.vbs, which contains VBScript code obfuscated by the same algorithm as for all other files. Figure 25 below shows its deobfuscated version.
![Screenshot of a Visual Studio Code interface showing a section of JavaScript code to create an object named WScript.shell.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-674985-143320-25.png) Figure 25. VBScript code of 1.vbs as shown in [Visual Studio Code](https://code.visualstudio.com/).

The last function Work continuously interacts with the C2 server, cycling through a set of operations as shown in Figure 26. This function is similar to the procedure of the PE variant. It periodically uploads the collected data and provides the attacker with backdoor functionality. This includes uploading any additional files to the C2 server or downloading and running additional PowerShell payloads to the victim's system.
![Screenshot of a computer script in a programming interface for the function Work, including function definitions and commands primarily related to web operations. The syntax is highlighted for readability.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-677958-143320-26.png) Figure 26. Excerpt of the Work function as shown in [Visual Studio Code](https://code.visualstudio.com/).

The control flow is as follows:

1. The function is initiated by pausing for 600 seconds.
2. It then constructs a URL *\<C2URL\>* ?id=*\<UUID\>*\&ap=1 to upload a file named k.log to the C2 server. The keylogger module creates this file.
3. After the upload, the function deletes the file k.log from the local machine.
4. It downloads a string from a server URL *\<C2URL\>*?id/rd and splits it into lines. For each line, which is a provided file path, it constructs a URL *\<C2URL\>* ?id=*\<UUID\>* and uploads the file to the server. Afterwards, it sends a GET request to a URL *\<C2URL\>* ?id=*\<UUID\>*\&del=rd to delete the read string from the server.
5. Next, it downloads a string from another server URL *\<C2URL\>*?id/wr and splits it into lines. For each line, it extracts the filename, constructs a URL *\<C2URL\>* ?id=*\<UUID\>* /*\<FileName\>* and downloads this file from the server to the victim's system. It then sends a GET request to a URL *\<C2URL\>* ?id=*\<UUID\>* \&del=*\<FileName\>* to delete the file from the server.
6. It downloads a string from a C2 server URL *\<C2URL\>*?id/cm and executes the string as a command using Invoke-Expression. This string can be any PowerShell code but is likely used to run additional payloads dropped previously. After execution, it sends a GET request to a URL *\<C2URL\>* ?id=*\<UUID\>*\&del=cm to delete the string on the server.
7. The function repeats this entire process indefinitely.

During our analysis of this malware, we did not observe any data returned from the C2 server.

The last of the three parts of the stealer's code is the main function logic shown in Figure 27.
![A screenshot of a computer script in a text editor, including various command lines and a PowerShell command, which is prominent in the display. The script includes tasks like registering a task, initiating and getting browser data.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-680929-143320-27.png) Figure 27. Main function logic as shown in [Visual Studio Code](https://code.visualstudio.com/).

First, this section creates the malware persistence in the registry and then collects system information and browser data. Next, it runs the file 2.log using the PowerShell loader script 1.ps1 before it finally sends all data to the C2 server and waits for the attacker's commands.

The file 2.log is a keylogger module that captures and records keystrokes, window titles and clipboard content as shown in Figure 28. This module writes the recorded data into a log file named k.log, which is uploaded to the C2 server in the Work function.
![Screenshot of a computer script displayed in a text editor with dark background, showing several lines of code written in PowerShell for the Keylog function. The code involves functions related to capturing and managing keyboard input.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-683896-143320-28.png) Figure 28. Base64-decoded keylogger code of 2.log as shown in [Visual Studio Code](https://code.visualstudio.com/).

## Previous Version of KimJongRAT PowerShell Variant

We've found a previous version of the PowerShell variant that only differs slightly from the most recent one. The main differences are in the PowerShell script in the stealer.

The [initial LNK file](https://www.virustotal.com/gui/file/28f2fcece68822c38e72310c911ef007f8bd8fd711f2080844f666b7f371e9e1) downloads an HTA file named prevenue.hta from an attacker-controlled cdn.glitch\[.\]global URL. The URL to the HTA file contains the value 1742020326408 for the parameter v. This value is the time in epoch format for Saturday, March 15, 2025, 6:32 a.m. (GMT). The LNK file's metadata is identical to the one used in the most recent version.

The [downloaded HTA file](https://www.virustotal.com/gui/file/3c2ea04090ad8c28116c42a9a2be5b240f135ac184e5a2c121b4eb311a7bf075) named prevenue.hta is almost identical to the HTA file used in the most recent version. The only differences are the [embedded decoy PDF file](https://www.virustotal.com/gui/file/48fc82c91f86fe783f9c0e2ec46f5b48aae3fd08c94342576eb194b0c9bb1de6) dropped as revenue.pdf and the embedded ZIP archive containing a previous version of the PowerShell stealer.

The decoy PDF file shown in Figure 29 seems to be a tax revenue-related document of a person from the South Korean city of Sejong.
![Image shows a form featuring various sections with personal details, registration number, and a QR code, all displayed in Korean characters.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-686970-143320-29.png) Figure 29. PDF decoy document revenue.pdf as shown in [Adobe PDF Reader](https://www.adobe.com/acrobat/pdf-reader.html).

Figure 30 shows the contents of the ZIP archive again dropped as pipe.zip.
![A screenshot showing a list of four files in a file explorer, detailing their size, packed size, modified, created, and accessed dates, as well as attributes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/06/word-image-690347-143320-30.png) Figure 30. Files contained in pipe.zip as shown in [7-Zip](https://www.7-zip.org/).

The only files that differ are [1.log](https://www.virustotal.com/gui/file/b1f9b450b97320de54f2450ace151b4f16444dc871f5e89487d52d862ce13cc2), which contains Base64-encoded text for the PowerShell stealer, and [2.log](https://www.virustotal.com/gui/file/12a00489c8c646e2f558778491751dec9fe6ff1339f7705866f0d7a97123055e), which contains Base64-encoded text for the keylogger module. The PowerShell stealer is an older version that uses the system's BIOS serial number instead of the UUID, among other minor differences. The keylogger module is also an older version that uses the BIOS serial number.

## Conclusion

Since it first emerged in 2019, the KimJongRAT stealer has evolved, adapting to the changing cybersecurity landscape. Our [previous article](https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/) highlighted the older variants of this malicious tool, and this article delves deeper into its latest incarnations. One variant uses a PE file, and another is a PowerShell implementation. This adaptability not only showcases the persistent threat posed by such malware but also underscores its developers' commitment to updating and expanding its capabilities.

This new analysis reveals the PowerShell variant's special focus on cryptocurrency, as it searches for an extensive list of browser wallet extensions.

The continued development and deployment of KimJongRAT, featuring changing techniques such as using a legitimate CDN server to disguise its distribution, demonstrates a clear and ongoing threat. Our comprehensive examination of these new variants provides crucial insights into their operation, aiding in the ongoing efforts to detect, neutralize and mitigate their effects.

Palo Alto Networks customers are better protected from the threats described in this article in the following ways:

* The [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire) machine-learning models and analysis techniques have been reviewed and updated in light of the IoCs shared in this research
* [Advanced URL Filtering](https://docs.paloaltonetworks.com/advanced-url-filtering/administration) and [Advanced DNS Security](https://docs.paloaltonetworks.com/dns-security) identify known URLs and domains associated with this activity as malicious
* [Advanced Threat Prevention](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration) has an inbuilt machine learning-based detection that can detect exploits in real time.
* [Cortex XDR](https://docs-cortex.paloaltonetworks.com/p/XDR) and [XSIAM](https://docs-cortex.paloaltonetworks.com/p/XSIAM) are designed to prevent the execution of known malicious malware, and also prevent the execution of unknown malware using Behavioral Threat Protection and machine learning based on the Local Analysis module.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42)
* UK: +44.20.3743.3660
* Europe and Middle East: +31.20.299.3130
* Asia: +65.6983.8730
* Japan: +81.50.1790.0200
* Australia: +61.2.4062.7950
* India: 00080005045107

Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

### **SHA256 Hashes of Initial LNK Files**

* a66c25b1f0dea6e06a4c9f8c5f6ebba0f6c21bd3b9cc326a56702db30418f189
* 28f2fcece68822c38e72310c911ef007f8bd8fd711f2080844f666b7f371e9e1
* 3b0a3bd5b790e5f130e7819550613b7e0194a3475f553285a1b7dc18ecca9d02
* 8a000aa43c17250dd02f842bc2ab37e47dd8d68da0d59753943df8b37004b701
* b90b2d992b41d146e70b775e2bc0430b9f7fb0ed0cd285c59daea92c2fc6af0b
* d92b858d691c84b4e3752fdd46b5673fbd6b5af101a7111c1d8756c90271b732
* be080777332ad1186fb8547a6a354b2beba62f2a24537eb7b79e849f084a95be

### **SHA256 Hashes of First Stage HTA Files**

* 02783530bbd8416ebc82ab1eb5bbe81d5d87731d24c6ff6a8e12139a5fe33cee
* 3c2ea04090ad8c28116c42a9a2be5b240f135ac184e5a2c121b4eb311a7bf075
* 9c9136fc8a279ce395997dd42c075e265c6daec14b13bbe4237a4178769d270e
* 9bfbf7618a2c5270d552f4deb69b56082cc7723433a1517678863363cb800161
* 6347d70b73e1cabadf8af8602b22a8220ed5b7298dbc15f16eb7dd493d6c6a78
* b7dad38a099947612fcc42c50f4ba1708af969a3222b3345bdff35323a41974d
* bcdc99e0f17486aa5a5faa0b9e7d7ccbeaa5372626733433214bb722ba260234
* 45980cc8afb4e1b3738130d0855bb608530eef6731c5116fd053ac6e04159725
* 7a37e2d6dc941386d1f300bac48056030f37c950bcd441d83eca708d2beab939

### **SHA256 Hashes of Second Stage Loader Files (baby.dll)**

* f4d9547269e0cd7a0df97e394f688e0eb00b31965abd5e6ad67d373a7dc58f3b
* 7a9f4ca13aed4d6d8ba430bc2b2f5ac2e4f9c7b5de2f5d2ba5aada211059da73
* d7a61ab1b1eadd3b34386ec2a96324195ec25cd71fe4e5d9a8f993a6bd52eb92
* 945e4f78196ef3a5548996a8d09e4220b779a2e78d40a86d64f233f7908550e6
* 5a18a29791cfb18767a43bebb61f923e64be7988235213678514007174f60b3e
* 4b87b775cdb265ecd872a71be810d7816d0d8b54663b3c536862db098874f288
* 8b0b62a31b348c5a2337ee69cfd3f68a427466539484f55f1cd2910237b59700
* 9e4e45e8f12db94997767bd3899968b9bc147bf08c062d3caea7f0864a67ea2c

### **SHA256 Hashes of KimJongRAT Orchestrator Files (NetworkService.dll)**

* 85be5cc01f0e0127a26dceba76571a94335d00d490e5391ccef72e115c3301b3
* bdb272189a7cdcf166fce130d58b794b242c582032f19369166b3d4cfdc0902c
* 2ba3397cba28af1a929403910035b78bf946acbafe9e186ac329b55086fe7703
* accf50d769408253bf9a7da378228debce7c8f6d60fb76da48196fe42cacedf3

### **SHA256 Hashes of KimJongRAT Stealer Files (dwm.dll, UPX packed)**

* 96df4f9cb5d9cacd6e3b947c61af9b8317194b1285936ce103f155e082290381
* c356cd9fea07353a0ee4dfd4652bf79111b70790e7ed63df6b31d7ec2f5953d5
* 5097553dff2a2da4f16b80a346fe543422b22d262e0c40e187b345afbcc7d41a
* ef0ce406fa722d30bfa094c660e81ed4a72ff8c75a629081293f4a86e0e587c2

### **SHA256 Hash of PowerShell Loader File**

* 97d1bd607b4dc00c356dd873cd4ac309e98f2bb17ae9a6791fc0a88bc056195a

### **SHA256 Hashes of PowerShell Stealer Files**

* b103190c647ddd7d16766ee5af19e265f0e15d57e91a07b2a866f5b18178581c
* eb68ed54e543c18070e5cc93a27db4a508d79016c09e28a47260ca080110328f

### **SHA256 Hashes of PowerShell Keylogger Files**

* 3c6476411d214d40d0cc43241f63e933f5a77991939de158df40d84d04b7aa78
* 4e45009f5b582ca404b197d28805e363a537856b55e39c5c806fcf05acd928ff

### **SHA256 Hash of Persistence VBS File**

* f73164bd4d2a475f79fb7d0806cfc3ddb510015f9161e7dce537d90956c11393

### **CDN Stager (Base) URLs**

* cdn.glitch\[.\]global/2eefa6a0-44ff-4979-9a9c-689be652996d/
* cdn.glitch\[.\]global/17443dac-272c-421c-80ac-53a3695ede0e/
* cdn.glitch\[.\]global/c97fe797-45c1-473b-a2f8-3c0c8bb431af/
* cdn.glitch\[.\]global/59e3786e-8284-4f16-8844-134b12e58b6f/
* cdn.glitch\[.\]global/4ab4f138-6f66-4b39-a7dc-9d4843dcf34f/

### **C2 (Base) URLs**

* 131\.153.13\[.\]235/sp/
* 131\.153.13\[.\]235/service/
* secservice.ddns\[.\]net/service2/
* srvdown.ddns\[.\]net/service3/

## Additional Resources

* [New BabyShark Malware Targets U.S. National Security Think Tanks](https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/) - Palo Alto Networks Unit 42
* [BabyShark Malware Part Two -- Attacks Continue Using KimJongRAT and PCRat](https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/)- Palo Alto Networks Unit 42
* [KimJongRAT/stealer malware analysis \[PDF\]](https://malware.lu/assets/files/articles/RAP003_KimJongRAT-Stealer_Analysis.1.0.pdf) - Malware.lu CERT
* [Special mission 'Operation Giant Baby', approaching as a huge threat](https://blog-alyac-co-kr.translate.goog/2223?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp) - ESTsecurity

Back to top

### Tags

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")
* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")
* [Infostealer](https://unit42.paloaltonetworks.com/tag/infostealer/ "Infostealer")
* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Serverless Tokens in the Cloud: Exploitation and Detections](https://unit42.paloaltonetworks.com/serverless-authentication-cloud/ "Serverless Tokens in the Cloud: Exploitation and Detections")

### Table of Contents

* 

### Related Articles

* [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "article - table of contents")
* [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "article - table of contents")
* [Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation](https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-analysis/ "article - table of contents")

## Related Resources

![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
