KRNRAT

Malware type
backdoor, rat, rootkit
Family
Malware family
Profile updated
2026-07-07 13:16:11

Context

According to Trend Micro, this is a rootkit with capabilities of a full-featured backdoor with various capabilities, including process manipulation, file hiding, shellcode execution, traffic concealment, and C&C communication. It is controlled through a range of IOCTL codes.

Reports & references

  • Trend Micro — Earth Kurma Apt Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Krnrat (report)

External references