EndClient RAT Exploits Stolen Certificate for Evasion

08 Nov 2025

The EndClient RAT, a Remote Access Trojan, is targeting human rights defenders in South Korea and beyond, utilizing a stolen code-signing certificate to evade detection. First identified on 2025-11-06 through a collaboration with PSCORE, the malware mimics legitimate applications, bypassing Windows defenses.

Code-signing and Delivery

The RAT is delivered via a Microsoft Installer (MSI) named 'StressClear.msi', using a stolen certificate from Chengdu Huifenghe Science and Technology Co Ltd. The legitimate guise allows it to avoid SmartScreen alerts. Additionally, it bundles a genuine module from WIZVERA VeraPort's Delphino to mislead users.

Functionality and Evasion Tactics

Upon execution, the malware releases an AutoIT-based payload. It maintains persistence by setting up a scheduled task in the user's system. The RAT employs a global mutex to prevent re-execution and initiates polymorphic changes if Avast antivirus is detected. It's designed to exchange data with a command-and-control server, offering functionalities like remote shell and file management.

Defensive Recommendations

Given its stealth, cybersecurity experts suggest blocking known indicators of compromise (IOCs) and scrutinizing 'StressClear.msi' files, along with monitoring any related scheduled tasks and mutex usage. This incident stresses the importance of joint efforts between civic and tech communities for enhanced security measures against complex threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6652868
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1389053
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
550074
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
460308
downloads

News and reviews for Desktop Windows

Death Stranding 2 PC Version Potentially Revealed by ESRB

A potential PC release of Death Stranding 2 was hinted at by an ESRB leak, suggesting changes in PlayStation's strategy.

Read more

Wildgate by Former StarCraft Devs Offers Fresh Gaming Experience

Moonshot Games' Wildgate, released 2025-11-26, brings unique mechanics and strategic balance. Now half-price on Steam.

Read more

Mounts Mayhem Update Hits Minecraft on 2023-12-09

Mojang's Mounts Mayhem update launches for Minecraft Java and Bedrock with new mounts, weapons, and features.

Read more

PowerDisplay to Simplify Multi-Monitor Setup on Windows 11

PowerToys introduces PowerDisplay for better multi-monitor control on Windows 11, expected January 2026.

Read more

Launch Announced for Pathbreakers: Roaming Blades RPG

6 Eyes Studio unveils Pathbreakers, a turn-based RPG in Stormtossed Isle with mercenary leads. Featuring mod support, it promises diverse gameplay.

Read more

Release Updated Elemental Evil on Steam This December

Sneg will release an upgraded Elemental Evil game on Steam on 2023-12-10, featuring enhanced gameplay and numerous improvements.

Read more

Sublustrum Set for 2026 PC and Console Release

Sublustrum, a 3D reimagining of Outcry, releases fall 2026 in multiple languages.

Read more

Judges Urge Halt of Trellix Antivirus Rollout

Bulgarian judges demand pausing Trellix deployment over data protection fears.

Read more

Xenopurge Offers Stressful Alien Warfare Experience

Xenopurge immerses players in a tactical roguelike where strategic keyboard commands decide clone marines' fates.

Read more

Death Stranding 2 PC Port Signals Rapid Release

The ESRB indicates Death Stranding 2 is set to release on PC soon. An announcement may come at The Game Awards.

Read more