A sophisticated Remote Access Trojan dubbed EndClient RAT has emerged as a significant threat targeting human rights defenders in North Korea, marking yet another escalation in advanced malware operations attributed to the Kimsuky.
See also: Using ClickFix techniques to install NetSupport RAT loaders

This newly discovered malware represents a worrying shift in the sophistication of attacks, using stolen code signing certificates to bypass antivirus protections and Windows SmartScreen.
The threat was first detected when a prominent North Korean human rights activist reported suspicious activity on her compromised account, prompting a broader investigation that revealed the scale and technical capabilities of the campaign. The attack chain demonstrates meticulous social engineering tactics combined with legitimate-looking delivery mechanisms.
The malware arrives via a deceptively named Microsoft Installer titled “StressClear.msi,” which was signed with stolen credentials from Chengdu Huifenghe Science and Technology Co Ltd, a Chinese mineral mining company. The perpetrators engage in direct, methodical conversations with targeted individuals, instructing them to download and run the MSI file.
This approach has proven effective, with at least 40 confirmed targets identified in the human rights community, although the full scope of the campaign remains unknown due to low antivirus detection rates.
Security analysts and researchers noted that the malware presents a combination of genuine software components along with malicious payloads, creating a complex deception that makes detection and analysis difficult. Upon execution, the MSI package installs a legitimate South Korean banking authentication module called Delfino by WIZVERA VeraPort, likely serving as bait to establish legitimacy.
See also: Phishing: Distribution of PureHVNC RAT via court documents

At the same time, the installer deploys a heavily obfuscated AutoIT script wrapped inside the genuine AutoIt3.exe binary , allowing the malware to run in memory while maintaining a low profile against security tools.
The combination of trusted processes and stolen signatures essentially allows the malware to gain unauthorized access to the system without triggering conventional security alarms. The EndClient RAT uses multiple layers of persistence mechanisms designed to survive system reboots and resist removal attempts.
Once installed, the malware establishes persistence via a scheduled task named “IoKlTr” that runs every minute from the Public\Music. The malware creates a globally named mutex identifier (Global\AB732E15-D8DD-87A1-7464-CE6698819E701) to prevent multiple instances from running concurrently, preventing resource exhaustion that could trigger detection.
When the malware detects the presence of Avast antivirus, it creates polymorphic variants of it by inserting junk data and creating new file names, demonstrating adaptive evasion capabilities. The malware also registers a startup link that launches the AutoIT malicious payload upon user login, ensuring consistent execution across reboots.
Communication with the command and control infrastructure is done over TCP socket connections using a custom protocol with JSON-based messages flanked by guard pointers (“endClient9688” and “endServer9688”), allowing the malware to receive commands for shell execution, file downloads, and data extraction.
See also: New polymorphic Python RAT changes with each execution

This technical architecture reveals a sophisticated understanding of Windows internals and shows how modern malware continues to abuse legitimate tools and signature mechanisms to bypass the security defenses that organizations rely on for protection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
