Skip to main content
Mallory
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

Black RAT

Black RAT is a remote access trojan associated with North Korean threat activity, specifically the Andariel group, a subordinate element within Lazarus and publicly tracked as Onyx Sleet. Reporting states Andariel has developed Black RAT as part of its broader custom RAT and implant arsenal. Black RAT was mentioned in connection with an attack campaign in which Andariel delivered Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers and through supply chain attacks involving South Korean asset management software. The broader Andariel activity is assessed as cyber espionage and ransomware-enabled operations targeting defense, aerospace, nuclear, and engineering organizations for sensitive military and technical information, with additional targeting of medical and energy sectors. The provided content does not include specific technical capabilities, persistence mechanisms, or indicators of compromise unique to Black RAT itself.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2021-44228Log4Shell

Over the last 15 years, the group has developed RATs, including the following... ▪ Black RAT

via ic3 alertsic3.gov
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Andariel

It also follows a new attack campaign orchestrated by the North Korea-linked Andariel group – another subordinate element within Lazarus – to deliver Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers as well as via supply chain attacks using a South Korean asset management software.

via the hacker newsthehackernews.com
Stonefly/Clasiopa

Over the last 15 years, the group has developed RATs, including the following... ▪ Black RAT

via ic3 alertsic3.gov
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1587.001MalwareEvidence2

“These tools include functionality for executing arbitrary commands... and uploading content to command and control (C2) [T1587.001, T1587.004].”

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence1

Andariel ... deliver Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers

T1195Supply Chain CompromiseEvidence1

Andariel ... deliver Black RAT, Lilith RAT, NukeSped, and TigerRAT by infiltrating vulnerable MS-SQL servers as well as via supply chain attacks using a South Korean asset management software.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.