KimJongRAT Malware Targets Windows Users via Phishing Campaign

KimJongRAT Malware Targets Windows Users via Phishing Campaign

First seen 2 Dec 2025, 19:40 UTC CybersecuritynewsScworld 86% similarity 39.6

Article Content

Browse articles
ThreatCluster

The KimJongRAT malware, linked to the North Korean Kimsuky group, is targeting Windows systems through phishing emails. These emails contain a ZIP archive disguised as a tax notice, which, when opened, executes a malicious HTA file using mshta to steal user credentials.

ThreatCluster AI How this analysis works

Community

Browse all →