POOLRAT, also known as SIMPLESEA, is a Lazarus-associated macOS backdoor linked to North Korean intrusion activity, including operations connected to the 3CX supply-chain compromise. It is part of a broader Lazarus toolset used for covert access and long-term operations, and has been referenced alongside related malware such as PondRAT. POOLRAT is characterized as a backdoor for macOS that supports remote command handling and has code and behavioral patterns shared with other Lazarus malware families. Reporting on related Lazarus tooling notes a distinctive secure file deletion routine involving repeated overwriting prior to deletion, a behavior associated with POOLRAT and closely related implants. The malware has been observed in persistence scenarios using Launch Daemons on compromised macOS systems. Activity involving POOLRAT has been associated with financially motivated North Korean clusters overlapping with Lazarus operations, particularly in campaigns affecting software supply chains and organizations of strategic or financial interest.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RemotePE also implements secure file deletion functionality by repeatedly overwriting files seven times prior to deletion, behavior previously associated with Lazarus-linked malware families such as PondRAT and POOLRAT.
One notable exception is the file deletion command, which overwrites each file with constant bytes seven times before renaming and deleting it, a secure deletion pattern consistent with PondRAT and POOLRAT, two malware families previously associated with this actor.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"The attackers behind this campaign uploaded several poisoned Python packages to PyPI..." ... "Successful installation of malicious third-party packages can result in malware infection that compromises an entire network."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked RAT family referenced because it shares secure file deletion behavior with RemotePE.
A Lazarus RAT mentioned for sharing a secure deletion pattern with RemotePE.
A malware family previously associated with the same actor; cited here because its secure deletion behavior resembles RemotePE's file deletion implementation.
Named in the IOC list as DPRK-linked malware associated with the investigated infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.