TigerRAT is a C++ remote access trojan for Windows associated with Andariel, a North Korean state-sponsored threat group also tracked as Silent Chollima and Onyx Sleet and linked to the Lazarus threat cluster. It has been used since around 2020 and was publicly disclosed by KISA and KrCERT in 2021 during Operation ByteTiger. Documented targets include South Korean defense, electronics, telecommunications, semiconductor, and engineering organizations, as well as a European public/legal-sector organization.
TigerRAT provides remote command execution, file management and transfer, system-information collection, screen capture, and self-deletion. Some variants additionally support keylogging, SOCKS tunneling, and port forwarding. Later versions introduced collection of data from USB devices, while port-forwarding support varies between versions. Its command-and-control communications use encrypted, HTTP-like traffic and an authentication exchange. Both 32-bit and 64-bit variants exist. Packed samples employ encrypted payloads, anti-analysis checks, junk code, and dynamic Windows API resolution to hinder analysis and detection. TigerRAT and TigerDownloader are code-distinct families that share a packing scheme.
Delivery chains have involved malicious documents, spearphishing attachments, compromised websites and watering-hole attacks, exploitation of Log4Shell in VMware Horizon, and abuse of a South Korean asset-management application. Additional downloaders and existing implants, including MagicRAT, have also delivered TigerRAT. Operators have used scheduled tasks to maintain access in TigerRAT deployment campaigns. The malware supports espionage and post-compromise control; it has also appeared in intrusions involving separate ransomware payloads, without itself being ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ASEC identified attacks against vulnerable Apache ActiveMQ servers and suspected Andariel exploited CVE-2023-46604 to install NukeSped and TigerRat. Direct logs proving the NukeSped installation occurred through this vulnerability were unavailable.
Andariel 그룹은 취약한 버전의 VMware Horizon 제품을 사용하는 국내 기업을 대상으로 Log4Shell 취약점 공격을 수행해 TigerRat을 설치한 사례도 존재한다. | 1.2.1. TigerRat TigerRat은 과거 한국인터넷진흥원(KISA)에서 이름붙인 RAT 악성코드로서 2020년 경부터 최근까지 Andariel 위협 그룹이 공격에 꾸준히 사용하고 있다.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This address, covered in a past Blog post, corresponds to the URL where TigerRat was downloaded from.
We call these the TigerDownloader and TigerRAT families, using names originally introduced by KrCERT.
Over the last 15 years, the group has developed RATs, including the following... ▪ TigerRAT
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Concerning the access methods, malicious documents have been used in the cases reported by Malwarebytes and Kaspersky, whereas a compromised website was used in the KrCERT case.
최근에는 Log4Shell 및 Innorix Agent 등 여러 프로그램에 대한 취약점들을 이용하여 국내 다양한 기업군에 공격을 해오고 있다.
지속성 유지를 위해 다음과 같은 명령을 실행하여 작업 스케줄러에 등록하였다. > schtasks /create /tn “microsoft\******” /tr “c:\users\%ASD%\credis.exe” /sc onlogon /ru system
The attribution was based on the threat actor’s usage of unique malware, such as TigerRAT, command execution patterns, infrastructure linkages, and other technical and non-technical evidence that linked it to previous reports of Andariel activity.
실제 다음과 같은 명령들을 실행한 로그도 확인된다. > cmd /c tasklist > cmd /c ipconfig /all
Malwarebytes has reported a recent attack targeting South Korea using a malicious Word document... Malwarebytes discovered a novel downloader component used in the attack.
The table below shows the MITRE ATT&CK Mapping after combining all these attacks/campaigns from previous reports and our analysis.
The table below shows the MITRE ATT&CK Mapping after combining all these attacks/campaigns from previous reports and our analysis.
In addition to this protocol change, we have also observed a change in the HTTP header that is sent at the beginning of the communication in the very first request by the RAT-KrCERT-x64 variant.
The new function essentially sends a 17-byte length chunk to the C2... Once the data is sent, it checks that the C2 returns the string “n0gyPPx.”
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as part of Silent Chollima's custom malware arsenal. The report provides no functionality details or confirmation of use in the reported campaign.
A remote access trojan deployed by Andariel in South Korea during an intrusion into an engineering company.
A remote access trojan used by Andariel as distinctive tooling supporting attribution of the intrusion.
A remote access trojan used by Andariel as distinctive tooling supporting attribution of the intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.