ForestTiger is a Windows backdoor associated with the DPRK-linked Lazarus Group, including activity tracked under Operation Dream Job and Diamond Sleet intrusions. It is used as a later-stage payload to provide persistent remote access on compromised hosts after initial delivery by other Lazarus tooling such as MISTPEN and, in some observed intrusion chains, Charamel Loader. Reported campaigns have targeted high-value organizations including defense, aerospace, aviation, software, and other strategically relevant sectors.
Observed delivery chains place ForestTiger behind recruiter- and job-themed social engineering. Lazarus has used spearphishing, trojanized software, malicious archives, and DLL sideloading to execute intermediate loaders and downloaders that ultimately deploy ForestTiger. In 2026 Dream Job activity, ForestTiger was delivered after an infection sequence involving a trojanized PDF viewer, an in-memory downloader, reconnaissance modules, persistence mechanisms, and local privilege escalation through exploitation of CVE-2026-68820, after which Lazarus deployed elevated tooling including FudModule. ForestTiger has also been reported in exploitation activity involving JetBrains TeamCity CVE-2023-42793.
ForestTiger functions as a long-term access backdoor within Lazarus post-compromise operations. Its role in observed campaigns is to maintain operator access after initial compromise and staging, enabling continued control of victim systems as part of broader espionage-oriented intrusion sets. Public reporting consistently places it within Lazarus’s modular malware ecosystem alongside loaders, downloaders, privilege-escalation components, and web-based relay infrastructure used to support stealthy command and control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final backdoor delivered by MISTPEN is the ForestTiger backdoor, a well-documented malware family widely attributed to the Lazarus threat group.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus backdoor used as the final payload for long-term remote access to compromised hosts.
A Lazarus backdoor used as the final persistence and remote access payload in one infection chain, providing long-term remote access to compromised hosts.
Backdoor deployed after exploitation of JetBrains TeamCity CVE-2023-42793; uses decrypted config for C2 and techniques such as DLL search-order hijacking to load further payloads.
A Lazarus malware family noted as one of the payloads delivered by Charamel Loader in a separate, unrelated attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.