Dora RAT is a Go-based remote access trojan associated with North Korea-linked Andariel, also tracked as Onyx Sleet and widely considered part of the Lazarus ecosystem. It has been observed in campaigns targeting South Korean organizations, including manufacturing, construction, and educational entities, and forms part of broader intrusion sets that also deploy backdoors, proxy tools, keylogging components, and file-stealing malware.
Dora RAT provides core remote administration functions including reverse shell access and file upload and download. Observed variants include a standalone executable form and an in-memory form injected into explorer.exe, indicating efforts to blend into legitimate processes and reduce detection. In at least one delivery chain, the malware was packaged through DLL side-loading using a self-extracting archive that launched a legitimate application while a malicious DLL decrypted an embedded Dora RAT payload and injected it into a running Windows process. Some samples were signed with valid code-signing certificates, further supporting defense evasion.
The malware has been linked to Andariel operations that commonly rely on spearphishing, watering-hole attacks, and exploitation of vulnerable internet-facing services for initial access, although the directly observed Dora RAT execution chain supports DLL side-loading as a concrete deployment mechanism. Dora RAT appears to be one component of a modular toolset: separate malware has been used alongside it for keylogging, clipboard capture, file theft, and proxying when those functions were not built into the RAT itself.
Dora RAT targets Windows systems and is used for post-compromise remote control and data theft support within espionage-oriented intrusions. Its development in Go aligns with a broader trend in recent Andariel tooling toward newly developed Go-based malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT observed delivered via DLL side-loading using WinRAR SFX packages.
Remote access trojan (noted as Go-based) used by Onyx Sleet.
A newly observed Go-based backdoor used by Andariel. The content describes it as a relatively simple RAT supporting reverse shell and file upload/download, delivered either as a standalone executable or injected into explorer.exe via a malicious version.dll loader.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.