SmallTiger is a Windows malware family used in intrusions targeting South Korean organizations, including defense contractors, semiconductor manufacturers, and automotive parts companies. It has been associated with North Korean activity, including reporting that links its use to APT45 (Andariel), and it appeared in operations that also showed overlaps with Kimsuky tradecraft. SmallTiger functions as a downloader that contacts command-and-control infrastructure, retrieves additional payloads, and executes them directly in memory. This behavior supports staged post-compromise operations while reducing on-disk exposure.
Observed campaigns using SmallTiger involved lateral propagation inside victim environments through abuse of enterprise software update mechanisms. In later activity, operators also used script-based staging to fetch and launch SmallTiger, including execution chains involving mshta, malicious JavaScript, alternate data streams, and rundll32. Distribution of additional SmallTiger payloads was also observed through GitHub-hosted content. The malware was deployed as part of broader intrusion sets that included credential theft and follow-on tooling such as LSASS dumping utilities, browser credential theft tools, remote administration utilities, and other post-exploitation frameworks.
Operationally, SmallTiger appears to serve as a lightweight in-memory delivery component within espionage-focused campaigns rather than as the final objective payload itself. Its role is to establish contact with attacker-controlled infrastructure, download secondary malware, and facilitate continued access and follow-on actions on compromised Windows systems. The targeting and surrounding tradecraft indicate use in sustained intelligence collection and internal network operations against strategically important South Korean industries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2024년 2월부터는 SmallTiger라고 이름 붙인 또 다른 악성코드를 사용하고 있다. ... 해당 악성코드는 다운로더로서 C&C 서버에 접속하여 페이로드를 다운로드해 메모리 상에서 실행하는 기능을 담당한다.
2024년 2월부터는 SmallTiger라고 이름 붙인 또 다른 악성코드를 사용하고 있다. ... 해당 악성코드는 다운로더로서 C&C 서버에 접속하여 페이로드를 다운로드해 메모리 상에서 실행하는 기능을 담당한다.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by North Korean actors, leveraging infrastructure mimicry and reconnaissance (as described).
Malware used by APT45/Andariel in targeting South Korean defense, semiconductor, and automotive manufacturing entities.
국내 기업 대상 공격에서 사용된 다운로더형 악성코드로, C&C 서버 또는 GitHub 등에서 추가 페이로드를 내려받아 메모리에서 실행한다. 내부 전파 과정에서 설치되며 DLL 형태로 배포되거나 mshta·rundll32·ADS를 이용해 실행된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.