Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We call these the TigerDownloader and TigerRAT families, using names originally introduced by KrCERT.
We call these the TigerDownloader and TigerRAT families, using names originally introduced by KrCERT.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
사용되는 API와 DLL 이름 등의 문자열을 암호화하여 저장하고 있다... C&C 서버의 주소는 DES ECB 알고리즘을 이용해 인코딩되어 있다.
Malwarebytes has reported a recent attack targeting South Korea using a malicious Word document... Malwarebytes discovered a novel downloader component used in the attack.
In addition to this protocol change, we have also observed a change in the HTTP header that is sent at the beginning of the communication in the very first request by the RAT-KrCERT-x64 variant.
37 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader component associated with TigerRAT, referenced as part of Operation ByteTiger.
A downloader malware family attributed in the report to Andariel/Lazarus-linked activity targeting South Korean entities. Variants include x86 and x64 builds; one x64 variant adds persistence by creating a shortcut in the current user startup folder. It is typically a 2nd-stage payload, communicates with C2 over web infrastructure, and downloads later-stage payloads including TigerRAT.
Downloader used in a watering-hole intrusion chain to install and launch NukeSped/TigerRAT. It collects host information, communicates with C2, and supports command execution, upload, download, thread termination, and C2 update.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.