TigerRAT is a Windows remote access trojan associated with the North Korea-linked Andariel threat group, a subgroup within the Lazarus cluster. It has been in sustained use since at least 2020 and has appeared across espionage-focused intrusions and broader multi-stage campaigns targeting South Korean organizations, including defense-sector entities, engineering firms, manufacturers, telecommunications and semiconductor companies, universities, and other institutions. It has also been observed in intrusions outside South Korea, including a European public/legal-sector case attributed to Andariel.
TigerRAT is typically deployed as a late-stage implant following initial compromise by other mechanisms. Reported delivery vectors include malicious documents, watering-hole compromises, exploitation of vulnerable internet-facing systems such as VMware Horizon through Log4Shell, abuse of vulnerable or poorly secured MS-SQL servers, and supply-chain style distribution through South Korean software or asset-management ecosystems. It has also been delivered by related downloader malware referred to as TigerDownloader and has been observed hosted alongside other Lazarus-associated implants such as MagicRAT and VSingle.
The malware provides standard RAT functionality for interactive post-compromise control. Across documented variants, capabilities include arbitrary command execution or shell access, file upload and download, file management, system information gathering, screen capture, keylogging, SOCKS tunneling, and in some versions port forwarding. Some reporting also describes self-deletion support. Newer variants have been reported with additional removable-media collection functionality and preparatory code for webcam capture, while at least one later version removed port-forwarding support. Communications are disguised as HTTP-like traffic and include custom registration or authentication exchanges; multiple variants use encrypted or obfuscated network protocols.
TigerRAT exists in multiple x86 and x64 variants. Analyses have shown that while TigerRAT is code-distinct from TigerDownloader, both families share a common packing scheme featuring in-memory payload decryption and mapping, anti-analysis measures, and dynamic API resolution. This packaging and the malware’s evolving command set indicate continued maintenance by its operators.
TigerRAT is a recurring component of Andariel operations that blend cyber espionage with financially motivated activity. It has been linked to campaigns involving privilege escalation, proxying and tunneling, credential collection, internal reconnaissance, and attempted follow-on ransomware deployment. Its repeated use across Andariel intrusions makes it a notable long-lived Lazarus-associated RAT in operations against South Korean and other strategically relevant targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Andariel 그룹은 취약한 버전의 VMware Horizon 제품을 사용하는 국내 기업을 대상으로 Log4Shell 취약점 공격을 수행해 TigerRat을 설치한 사례도 존재한다. | 1.2.1. TigerRat TigerRat은 과거 한국인터넷진흥원(KISA)에서 이름붙인 RAT 악성코드로서 2020년 경부터 최근까지 Andariel 위협 그룹이 공격에 꾸준히 사용하고 있다.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attribution was based on the threat actor’s usage of unique malware, such as TigerRAT, command execution patterns, infrastructure linkages, and other technical and non-technical evidence that linked it to previous reports of Andariel activity.
We call these the TigerDownloader and TigerRAT families, using names originally introduced by KrCERT.
Over the last 15 years, the group has developed RATs, including the following... ▪ TigerRAT
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Concerning the access methods, malicious documents have been used in the cases reported by Malwarebytes and Kaspersky, whereas a compromised website was used in the KrCERT case.
최근에는 Log4Shell 및 Innorix Agent 등 여러 프로그램에 대한 취약점들을 이용하여 국내 다양한 기업군에 공격을 해오고 있다.
지속성 유지를 위해 다음과 같은 명령을 실행하여 작업 스케줄러에 등록하였다. > schtasks /create /tn “microsoft\******” /tr “c:\users\%ASD%\credis.exe” /sc onlogon /ru system
The attribution was based on the threat actor’s usage of unique malware, such as TigerRAT, command execution patterns, infrastructure linkages, and other technical and non-technical evidence that linked it to previous reports of Andariel activity.
실제 다음과 같은 명령들을 실행한 로그도 확인된다. > cmd /c tasklist > cmd /c ipconfig /all
Malwarebytes has reported a recent attack targeting South Korea using a malicious Word document... Malwarebytes discovered a novel downloader component used in the attack.
The table below shows the MITRE ATT&CK Mapping after combining all these attacks/campaigns from previous reports and our analysis.
The table below shows the MITRE ATT&CK Mapping after combining all these attacks/campaigns from previous reports and our analysis.
In addition to this protocol change, we have also observed a change in the HTTP header that is sent at the beginning of the communication in the very first request by the RAT-KrCERT-x64 variant.
The new function essentially sends a 17-byte length chunk to the C2... Once the data is sent, it checks that the C2 returns the string “n0gyPPx.”
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan deployed by Andariel in South Korea during an intrusion into an engineering company.
A remote access trojan used by Andariel as distinctive tooling supporting attribution of the intrusion.
A remote access trojan used by Andariel as distinctive tooling supporting attribution of the intrusion.
C++ remote access trojan with file control, command execution, SOCKS tunneling, and encrypted HTTP-like communications; used in defense-sector intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.