Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

EarlyRat is a simple malware family that Kaspersky reported in June 2023 while investigating activity linked to North Korean threat group Andariel. In the analyzed samples, it collected system information, contacted command-and-control (C2) infrastructure, and could execute commands. Kaspersky observed both a Log4j-associated case and phishing documents that dropped EarlyRat; it did not establish one delivery route for every infection.

What is EarlyRat malware?

EarlyRat is a previously undocumented malware family identified by researchers at Kaspersky’s Global Research and Analysis Team (GReAT) and ICS CERT. Their report, published June 28, 2023, emerged from an investigation into Andariel-related activity. Kaspersky characterized EarlyRat as very simple, with command execution as its principal notable function.

The name refers to the malware Kaspersky analyzed, not a broader Andariel toolset. The report does not establish EarlyRat as ransomware, nor does it document a measured number of victims or infections. Kaspersky’s technical report describes the samples and their observed behavior.

How does Andariel deliver EarlyRat?

Kaspersky described two contexts in its investigation, not a single confirmed delivery chain that applies to every sample.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Log4j-associated case

In one observed case, exploitation of Log4j was followed by downloads that included DTrack. Researchers initially assumed EarlyRat had also arrived through Log4j, but that assumption was not confirmed as a universal route.

Phishing documents

After searching for additional samples, the researchers found phishing documents that ultimately dropped EarlyRat. The analyzed document used a macro, and its VBA code contacted a server associated with the HolyGhost/Maui ransomware campaign. This connects that document’s context to the infrastructure observation; it does not show that EarlyRat is ransomware or that all EarlyRat infections use that server or phishing.

What can EarlyRat do?

When started, EarlyRat gathers system information and sends it to C2 infrastructure. Kaspersky documented protocol fields that include an ID value and a query value. The query content is Base64-encoded and further obfuscated with a rolling XOR scheme that uses the ID as a key.

The report’s main functional point is command execution. Kaspersky compared EarlyRat’s limited functionality with MagicRat, while distinguishing their development frameworks: EarlyRat was written in PureBasic, whereas MagicRat was written in Qt. This comparison does not mean the two malware families are the same.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is EarlyRat linked to Andariel?

Kaspersky reported EarlyRat during an investigation into Andariel-related activity. That places the malware in the context of the activity the researchers examined, but it does not justify assigning every Andariel operation or tool to EarlyRat.

In its broader campaign account, Kaspersky describes Andariel’s use of DTrack and Maui ransomware in mid-2022, Log4j exploitation, and tools including Supremo, 3Proxy, Powerline, PuTTY, Dumpert, NTDSDumpEx, and ForkDump. These are campaign-level details, not a list of tools delivered by EarlyRat. Kaspersky’s report discusses the wider activity alongside its EarlyRat findings.

Who does Andariel target, and what is its wider purpose?

A joint advisory summarized by the UK National Cyber Security Centre (NCSC) on July 25, 2024 assessed Andariel as part of North Korea’s Reconnaissance General Bureau 3rd Bureau. It said the group primarily targeted defence, aerospace, nuclear, and engineering organizations, and less often medical and energy organizations. The stated aim was to obtain sensitive technical information and intellectual property, such as contract specifications, design drawings, and project details. The NCSC summary describes these targets and objectives as part of Andariel’s broader activity.

The NCSC said the advisory described exploitation of known software vulnerabilities to gain access, followed by malware and other tools used for persistence, evasion, and exfiltration. It also reported ransomware attacks against U.S. healthcare organizations to fund espionage, with some victims experiencing espionage and ransomware on the same day. Those behaviors belong to the wider campaign reporting; they are not capabilities demonstrated for EarlyRat.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A U.S. Department of Justice (DOJ) release dated July 25, 2024, and updated February 6, 2025, describes charges against North Korean national Rim Jong Hyok. Prosecutors alleged that he and co-conspirators worked for North Korea’s Reconnaissance General Bureau, extorted U.S. hospitals and healthcare providers using Maui ransomware, laundered ransom proceeds, and used funds for later intrusions into defense, technology, and government entities worldwide. The DOJ release uses Andariel, Onyx Sleet, and APT45 as private-sector names for the actors. It also emphasizes that an indictment contains allegations and defendants are presumed innocent. Read the DOJ release and its qualification.

For historical context, the U.S. Treasury’s September 13, 2019 designation release identified Andariel as a North Korean state-sponsored group tied to the Reconnaissance General Bureau, describing operations against South Korean government and infrastructure targets that included intelligence collection and cybercrime for revenue. That is historical government attribution, not proof about the specific EarlyRat samples reported in 2023. Treasury’s designation announcement gives that earlier account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why do sources use different names for Andariel?

Threat-intelligence organizations do not always draw group boundaries or assign aliases in the same way. MITRE ATT&CK lists Silent Chollima, PLUTONIUM, and Onyx Sleet as associated names for its Andariel profile, while warning that definitions of North Korean groups can overlap significantly. The DOJ’s 2024 release also uses APT45. Treat these as source-specific naming choices rather than assuming every name is an exact synonym in every vendor’s taxonomy. MITRE ATT&CK’s Andariel profile explains its aliases and naming caveat.

What should defenders take from the report?

EarlyRat’s observed functions point to practical monitoring priorities, while Andariel’s broader reported methods make vulnerability and incident-response readiness relevant at the organizational level. The cited reporting does not endorse a particular security product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Reduce known-exploit exposure: Maintain vulnerability and patch management for internet-facing and other exposed systems, given the wider reporting on exploitation of known vulnerabilities.
  • Monitor execution and communications: Endpoint and network monitoring can help identify suspicious command execution, system-information collection, and C2 activity. These are useful detection areas based on the behavior Kaspersky describes; the report does not provide a universal signature or guarantee of detection.
  • Prepare for containment and evidence preservation: Incident response readiness matters for investigating intrusions and distinguishing malware findings from the broader activity in which they occur.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.