Nestdoor is a Windows remote access trojan associated with the North Korean state-linked Andariel intrusion set, which is part of the broader Lazarus ecosystem. It has been observed since at least 2022 in campaigns targeting South Korean organizations, including manufacturing, construction, and educational entities, and has also been linked to exploitation activity involving vulnerable public-facing servers such as VMware Horizon systems affected by Log4Shell. Nestdoor has repeatedly appeared alongside other Andariel tooling, including TigerRAT, proxy utilities, web shells, stealers, and separate keylogging components.
Nestdoor provides remote control of infected systems by receiving operator commands from command-and-control infrastructure. Reported capabilities include file operations and reverse shell access, enabling operators to execute commands and manage victim-host data after compromise. Variants observed in later campaigns retained core remote-control and obfuscation behavior while exposing a reduced command set compared with earlier samples. Nestdoor has also been observed establishing persistence through Windows Scheduled Tasks.
Distribution has included both post-exploitation deployment after server compromise and delivery disguised as legitimate software. In one observed campaign, operators compromised an outdated Apache Tomcat server and used it to distribute malware. In another, Nestdoor was masqueraded as OpenVPN software, reflecting Andariel’s broader use of deceptive packaging and signed malware in some operations. Operationally, Nestdoor is part of a wider espionage toolkit used to maintain access, support hands-on-keyboard activity, and facilitate data theft from targeted environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2022년 6월 미국 CISA에서는 VMware Horizon 제품의 Log4Shell 취약점(CVE-2021-44228)을 악용하여 악성코드를 설치하는 공격 사례들을 분석하여 공개하였다. | Nestdoor는 적어도 2022년 5월 경부터 확인되고 있는 RAT 악성코드이다. 공격자의 명령을 전달받아 감염 시스템을 제어할 수 있으며 Andariel 그룹의 공격 사례에서 지속적으로 확인되고 있다.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Nestdoor는 적어도 2022년 5월 경부터 확인되고 있는 RAT 악성코드이다. 공격자의 명령을 전달받아 감염 시스템을 제어할 수 있으며 Andariel 그룹의 공격 사례에서 지속적으로 확인되고 있다.
Nestdoor는 적어도 2022년 5월 경부터 확인되고 있는 RAT 악성코드이다. 공격자의 명령을 전달받아 감염 시스템을 제어할 수 있으며 Andariel 그룹의 공격 사례에서 지속적으로 확인되고 있다.
Over the last 15 years, the group has developed RATs, including the following... ▪ Nestdoor
11 distinct techniques documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Andariel-associated RAT/backdoor used to control infected systems. The content says it supports file upload/download, reverse shell, command execution, and in some variants proxy-related capabilities; newer samples retain core control functions and persistence via scheduled tasks while communicating with C2.
Backdoor used to maintain access and support operations (specific functionality not detailed in the advisory).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.