KimJongRAT Description

The KimJong malware is a RAT (Remote Access Trojan) that is likely to originate From North Korea The KimJong malware has been involved in similar campaigns of another threat that is likely North Korean – the BabyShark malware. The BabyShark malware targeted entities, which were linked to the proposed denuclearization of North Korea. It was discovered that many of the systems infected with the BabyShark malware also were infiltrated by the KimJongRAT. When these campaigns were further studied, malware experts found out that the two threats worked in unison – the BabyShark malware allowed the KimJongRAT to gain access to the compromised systems. Having in mind the political nature of the targets, it is easy to speculate that the attackers may be linked to the North Korean government in some way.

It would seem that the authors of the KimJongRAT did not take advantage of all the capabilities of this high-end malware, which could have granted them with almost unlimited control over the compromised machine. Instead, the attackers have chosen only to collect login credentials and some other data. The data gathered would be stored in a file called 'ttmp.log,' which is another stark similarity to the aforementioned BabyShark malware, which also stores its collected data in a 'ttmp.log' file.

The KimJongRAT has been programmed to siphon data from popular Web browsers such as Google Chrome, Mozilla Firefox, Internet Explorer and Yandex Browser. This threat also targets several Web pages and online services – Facebook, Google, Yahoo, Mozilla Thunderbird and Microsoft Outlook.

It is likely that the full capabilities of the KimJongRAT are not employed because these initial campaigns only serve to monitor the victims with the end goal of collecting data, which would then help the attackers craft more believable spear-phishing email campaigns for much more damaging future operations.

Do You Suspect Your PC May Be Infected with KimJongRAT & Other Threats? Scan Your PC with SpyHunter

SpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like KimJongRAT as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Note: SpyHunter's scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. Free Remover allows you to run a one-off scan and receive, subject to a 48-hour waiting period, one remediation and removal. Free Remover subject to promotional details and Special Promotion Terms. To understand our policies, please also review our EULA, Privacy Policy and Threat Assessment Criteria. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?

Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.
If you still can't install SpyHunter? View other possible causes of installation issues.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.