POOLRAT is a cross-platform backdoor associated with North Korea’s Lazarus Group, with variants documented for macOS, Linux, and Windows. It provides remote command execution and uses anti-forensic file-deletion routines that overwrite and rename files before removing them. Its Linux and macOS variants share closely matching configuration-loading structures, strings, and command-handling mechanisms.
POOLRAT was deployed on 3CX’s macOS build server during the intrusion associated with the 2023 3CX software supply-chain compromise, using Launch Daemons for persistence. It was also observed alongside ThemeForestRAT in a 2020 incident involving a financially motivated Lazarus subgroup targeting financial and cryptocurrency organizations. Linux variants have additionally been distributed through malicious Python packages hosted on PyPI, exposing developer environments to compromise.
POOLRAT is closely related to PondRAT, which has been assessed as a lighter successor. The families share naming conventions, XOR-key material, shell-command formatting, bot-identifier generation concepts, command-response construction, and secure-deletion behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“In the incident response case from 2020 we encountered POOLRAT in combination with ThemeForestRAT.”
One notable exception is the file deletion command, which overwrites each file with constant bytes seven times before renaming and deleting it, a secure deletion pattern consistent with PondRAT and POOLRAT, two malware families previously associated with this actor.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"The attackers behind this campaign uploaded several poisoned Python packages to PyPI..." ... "Successful installation of malicious third-party packages can result in malware infection that compromises an entire network."
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-linked RAT family referenced because it shares secure file deletion behavior with RemotePE.
A Lazarus RAT mentioned for sharing a secure deletion pattern with RemotePE.
A malware family previously associated with the same actor; cited here because its secure deletion behavior resembles RemotePE's file deletion implementation.
Named in the IOC list as DPRK-linked malware associated with the investigated infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.