Skip to main content
Mallory
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

Lilith RAT

Lilith RAT is a remote access trojan referenced in reporting on North Korea-linked activity. It has been identified as an open-source or dual-use tool used and/or customized by the Andariel group, a subordinate element of Lazarus also tracked as Onyx Sleet. Reporting states Andariel used Lilith RAT alongside Black RAT, NukeSped, and TigerRAT in campaigns that infiltrated vulnerable MS-SQL servers and in supply-chain attacks involving South Korean asset management software. Separate reporting on a Konni/Kimsuky-linked campaign in South Korea states attackers used malicious attachments to deliver remote access trojans such as Lilith RAT in order to take over victims’ machines. The available content does not provide detailed technical functionality specific to Lilith RAT beyond its use as a RAT, nor does it include malware-specific IoCs, but it does note a detection reference: YARA rule "Andariel_LilithRAT_Variant."

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2021-44228Log4Shell

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Lilith RAT

via ic3 alertsic3.gov
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Andariel

It also follows a new attack campaign orchestrated by the North Korea-linked Andariel group – another subordinate element within Lazarus – to deliver Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers as well as via supply chain attacks using a South Korean asset management software.

via the hacker newsthehackernews.com
Stonefly/Clasiopa

The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Lilith RAT

via ic3 alertsic3.gov
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence1

Andariel ... deliver Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers

T1195Supply Chain CompromiseEvidence1

Andariel ... deliver Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers as well as via supply chain attacks using a South Korean asset management software.

Stealth

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

“...check for the existence of the WDAGUtilityAccount user folder... terminate... likely ... designed to run only within Windows Sandbox”

Discovery

1 technique
T1497Virtualization/Sandbox EvasionEvidence1

“...check for the existence of the WDAGUtilityAccount user folder... terminate... likely ... designed to run only within Windows Sandbox”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.