PostNapTea is a Lazarus Group-associated backdoor/RAT. The provided reporting states that Lazarus deployed PostNapTea against South Korean targets in 2022. ESET later identified substantial code overlap between PostNapTea and Tropidoor, a more recently observed backdoor used in the North Korea-aligned DeceptiveDevelopment/Contagious Interview ecosystem, suggesting malware sharing or reuse by more technically advanced actors under the broader Lazarus umbrella. PostNapTea is repeatedly described in the source material as a Lazarus RAT/backdoor and is mentioned alongside other Lazarus-linked malware families such as Manuscrypt, Volgmer, wAgentTea, and DRATzarus. High-confidence details in the content do not provide a full standalone technical profile for PostNapTea itself beyond its role as a backdoor/RAT, its Lazarus attribution, its use against South Korean targets in 2022, and its code relationship to Tropidoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers Peter Kálnai and Matěj Havránek identified new links between DeceptiveDevelopment's malware and the Lazarus Group's PostNapTea RAT.
"Also deployed as part of these infection sequences are TsunamiKit, PostNapTea, and Tropidoor..."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Tropidoor code supports several Windows commands including ... ping ... net ... nslookup
Tropidoor code supports several Windows commands including ... net (manage network resources and user accounts)...
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool referenced in TraderTraitor-related reporting.
Backdoor previously attributed to the Lazarus Group; referenced here due to code overlap with Tropidoor.
Backdoor previously attributed to the Lazarus Group; referenced here due to code overlap with Tropidoor.
A remote access trojan associated with Lazarus Group; Tropidoor shares large portions of code with it, and it was deployed against South Korean targets in 2022.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.