EndClientRAT Bypasses Security Using Stolen Code Signing

08 Nov 2025

A new campaign using the sophisticated EndClientRAT targets North Korean human rights defenders (HRDs), utilizing compromised code-signing to bypass antivirus protections. This malicious operation was discovered during a collaboration between independent security researchers and PSCORE.

Technical Details of the Attack

The campaign involves a malicious Microsoft Installer, 'StressClear.msi', which leverages stolen certificates from Chengdu Huifenghe Science and Technology Co Ltd, issued by SSL.com EV Code Signing Intermediate CA RSA R3. This certificate is valid from 2024-10-25 to 2025-10-17.

The EndClientRAT's low detection rate—only 7 out of 64 antivirus engines flagged the dropper—illustrates its stealth. It exploits a scheduled task named 'IoKlTr' for persistence and uses a mutex 'Global\AB732E15-D8DD-87A1-7464-CE6698819E701' to avoid multiple instances.

Targets and Tactics

The attackers compromised a prominent activist in September, remotely wiping the Android device and hijacking the KakaoTalk account to disseminate the RAT further. The campaign reached 39 additional targets using social engineering techniques. The package, AutoIT-based, operates with strong anti-analysis tactics and communicates with a command-and-control server, 116.202.99.218:443, using custom JSON protocols marked by 'endClient9688' and 'endServer9688'.

Mitigation and Recommendations

Security experts recommend monitoring for specific protocol markers within network traffic and suspicious artifacts in user directories. Organizations should distrust signed MSI files until their provenance is verified. Collaborative threat intelligence sharing and specialized support for at-risk civil society organizations are crucial in mitigating these targeted threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6398460
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1276363
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
495985
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453730
downloads

News and reviews for Desktop Windows

PC Gamer Features Heroes of Might and Magic: Olden Era

PC Gamer exclusively reveals Heroes of Might and Magic: Olden Era. Developer Unfrozen revives this classic series, blending nostalgia with modern elements.

Read more

EndClientRAT Bypasses Security Using Stolen Code Signing

EndClientRAT uses compromised code-signing in a campaign against North Korean rights defenders. Antivirus evasion and targeted attacks detailed.

Read more

Adds Baldur's Gate to Xbox Game Pass for PC

Baldur's Gate and its Enhanced sequel debut on Xbox Game Pass for PC today, despite an earlier delay. Expect enriched visuals and lengthy gameplay.

Read more

Curly COMrades Leverage Hyper-V for Stealthy Operations

Curly COMrades exploits Hyper-V on Windows for covert VM-based attacks, evading EDR detection.

Read more

Frontier Develops Planet Zoo Sequel for Future Release

Frontier Developments announces it is creating a sequel to Planet Zoo. Expected developments are to be revealed in 2026, delighting simulation fans.

Read more

Steam's Movember Bundle Offers $350 Games for $20

The Movember bundle by Fanatical offers $350 in Steam games for $20 this month, featuring prominent titles like Chivalry 2 and Gloomwood.

Read more

Paradox Enhances EU5 Performance Amid Initial Issues

Paradox Tinto tackles EU5 performance inconsistencies, offering fixes and optimizations to improve gameplay experience.

Read more

Hackers Use Linux Malware to Evade Windows Security

Attackers employ Linux malware on Windows for stealth, compromising security via Hyper-V.

Read more

Game Pass Drives Massive Play but Low Revenue for ‘Savage Planet’

Revenge of the Savage Planet sees high Game Pass player numbers, but revenue disappoints, says Creative Director Alex Hutchinson.

Read more

Launch Solasta 2 in Early Access Q1 2026

Solasta 2 enters early access in Q1 2026 with new features, expanding gameplay options for fans.

Read more