EndClient RAT Exploits Stolen Certificate for Evasion

08 Nov 2025

The EndClient RAT, a Remote Access Trojan, is targeting human rights defenders in South Korea and beyond, utilizing a stolen code-signing certificate to evade detection. First identified on 2025-11-06 through a collaboration with PSCORE, the malware mimics legitimate applications, bypassing Windows defenses.

Code-signing and Delivery

The RAT is delivered via a Microsoft Installer (MSI) named 'StressClear.msi', using a stolen certificate from Chengdu Huifenghe Science and Technology Co Ltd. The legitimate guise allows it to avoid SmartScreen alerts. Additionally, it bundles a genuine module from WIZVERA VeraPort's Delphino to mislead users.

Functionality and Evasion Tactics

Upon execution, the malware releases an AutoIT-based payload. It maintains persistence by setting up a scheduled task in the user's system. The RAT employs a global mutex to prevent re-execution and initiates polymorphic changes if Avast antivirus is detected. It's designed to exchange data with a command-and-control server, offering functionalities like remote shell and file management.

Defensive Recommendations

Given its stealth, cybersecurity experts suggest blocking known indicators of compromise (IOCs) and scrutinizing 'StressClear.msi' files, along with monitoring any related scheduled tasks and mutex usage. This incident stresses the importance of joint efforts between civic and tech communities for enhanced security measures against complex threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508630
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735697
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746791
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
497260
downloads

Comments (0)

No comments yet. Be the first to comment!