Scworld
KimJongRAT Malware Targets Windows Users via Phishing Campaign
First seen 2 Dec 2025, 19:40 UTC
•
•86% similarity
•39.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The KimJongRAT malware, linked to the North Korean Kimsuky group, is targeting Windows systems through phishing emails. These emails contain a ZIP archive disguised as a tax notice, which, when opened, executes a malicious HTA file using mshta to steal user credentials.
ThreatCluster AI
How this analysis works