EndClient RAT Exploits Stolen Certificate for Evasion

08 Nov 2025

The EndClient RAT, a Remote Access Trojan, is targeting human rights defenders in South Korea and beyond, utilizing a stolen code-signing certificate to evade detection. First identified on 2025-11-06 through a collaboration with PSCORE, the malware mimics legitimate applications, bypassing Windows defenses.

Code-signing and Delivery

The RAT is delivered via a Microsoft Installer (MSI) named 'StressClear.msi', using a stolen certificate from Chengdu Huifenghe Science and Technology Co Ltd. The legitimate guise allows it to avoid SmartScreen alerts. Additionally, it bundles a genuine module from WIZVERA VeraPort's Delphino to mislead users.

Functionality and Evasion Tactics

Upon execution, the malware releases an AutoIT-based payload. It maintains persistence by setting up a scheduled task in the user's system. The RAT employs a global mutex to prevent re-execution and initiates polymorphic changes if Avast antivirus is detected. It's designed to exchange data with a command-and-control server, offering functionalities like remote shell and file management.

Defensive Recommendations

Given its stealth, cybersecurity experts suggest blocking known indicators of compromise (IOCs) and scrutinizing 'StressClear.msi' files, along with monitoring any related scheduled tasks and mutex usage. This incident stresses the importance of joint efforts between civic and tech communities for enhanced security measures against complex threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6398925
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1276524
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
496002
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
453733
downloads

News and reviews for Desktop Windows

Tavern Keeper Offers Rich Early Access Experience in Fantasy Setting

Tavern Keeper, by Greenheart Games, impresses with engaging gameplay. Available in early access. Explore diverse realms and unique storytelling.

Read more

Netflix Acquires Rights for Overcooked TV Show

Netflix and A24 to transform Overcooked into a reality show; core team executive produce.

Read more

Tavern Keeper Achieves 'Overwhelmingly Positive' on Steam

Tavern Keeper, a pub sim by Greenheart Games, launched on 2023-11-03 and quickly earned overwhelming positive feedback. The result follows 11 years of development.

Read more

Arc Raiders Update: Key Quest Mechanics Explained

Explore Arc Raiders' What We Left Behind quest. Navigate Buried City, Spaceport, and Dam Battlegrounds for rewards and new quests.

Read more

Epic Store Offers Free Games This Week

Epic Store makes Felix The Reaper and Idle Champions available free from 2025-11-06.

Read more

Epic Games Offers Free Titles 'Felix the Reaper' and 'Idle Champions'

Epic Games releases two free games on 2025-11-06. Players can keep Felix the Reaper and Idle Champions perpetually after claiming them this week.

Read more

EU5 Console Commands Enhance Gameplay Flexibility

Discover how EU5 console commands offer flexibility for players. Useful cheats and Debug Mode improve gameplay experience.

Read more

Shroud Backs Arc Raiders for Game of the Year

Top streamer Shroud rallies support for Arc Raiders to win Game of the Year over Expedition 33 at The Game Awards.

Read more

Whiskerwood Opens Early Access with Mice Colony-Building Fun

Whiskerwood brings colony-building with mice to early access on Steam and PC Game Pass, promising strategic gameplay.

Read more

GeForce NOW Expands with Over 20 New Games in November

GeForce NOW adds 23 games, including Call of Duty: Black Ops 7, this November. Amsterdam gains RTX 5080 power. Impact expected in cloud gaming.

Read more