ScoringMathTea RAT is a remote access trojan attributed to the North Korean Lazarus Group and associated with espionage activity. Reporting describes it as a newly identified Lazarus malware family that uses a reflective plugin loader and custom polyalphabetic cryptography, indicating a modular design and bespoke encrypted communications or data handling. In an Operation DreamJob campaign observed by ESET, Lazarus targeted three European defense-sector companies, including organizations involved in unmanned aerial vehicle (UAV) technology and military equipment deployed in Ukraine. The infection chain used fake recruitment lures and trojanized open-source applications or plugins, including MuPDF viewer, Notepad++, WinMerge plugins, TightVNC Viewer, libpcre, and DirectX wrappers. The campaign relied on DLL sideloading and in-memory payload decryption/loading via MemoryModule-style routines to evade detection. ScoringMathTea was deployed as the final-stage malware, establishing command-and-control communications and awaiting instructions. It reportedly supports 40 commands, including command execution, file manipulation, and downloading additional payloads. High-confidence associated context includes Lazarus Group, Operation DreamJob, European defense/UAV targets, reflective plugin loading, custom polyalphabetic cryptography, and C2-based remote control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan (RAT) used for espionage, featuring a reflective plugin loader and custom polyalphabetic cryptography.
Remote access trojan used by Lazarus Group to gain persistent access, execute commands, manipulate files and processes, collect system information, and download additional payloads.
Remote access trojan (RAT) attributed to the Lazarus Group, likely used for persistent remote access and control of compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.