Researchers tied multiple malware samples used against South Korean organizations to two related Lazarus/Andariel families, TigerDownloader and TigerRAT, consolidating activity previously reported separately by Malwarebytes, Kaspersky, and KrCERT. The intrusions commonly began with Korean-language spearphishing documents that abused macros, saved content as HTML, extracted hidden objects from image files, and launched payloads through mshta.exe; in other cases, Lazarus-linked operators also used watering-hole and supply-chain delivery paths involving compromised Korean websites and software distribution mechanisms. Threat analysts found shared packing and decryption logic across the downloader and RAT families, including XOR- and Base64-based unpacking, while the implants used HTTP command-and-control and masqueraded traffic or payloads as benign content such as GIF uploads.
The malware provided broad remote access capabilities including shell execution, file management, screen capture, keylogging, SOCKS tunneling, port forwarding, self-deletion, and system reconnaissance, with some variants adding persistence through startup shortcuts and others introducing small command-and-control protocol changes such as the n0gyPPx registration check. Securelist also documented Andariel deploying a custom ransomware payload in at least one South Korea-focused intrusion, showing the subgroup combining espionage-style access with financially motivated operations. The reporting strengthens attribution of these campaigns to Andariel, a Lazarus subgroup, based on code overlap, encryption routines, post-exploitation tradecraft, and long-running targeting patterns against South Korean government, enterprise, and web infrastructure.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC reported that Lazarus was compromising Windows IIS servers and using them to distribute malware through exploitation of unpatched INISAFE CrossWeb EX vulnerabilities. The activity involved w3wp.exe-launched malware, a Themida-packed JuicyPotato variant for privilege escalation, and an in-memory loader that decrypted payloads disguised as GIF files.
Threatray concluded that malware samples previously discussed by Malwarebytes, Kaspersky, and KrCERT belonged to two related but code-distinct families named TigerDownloader and TigerRAT. The analysis linked the activity to Andariel and described shared packing, multiple downloader and RAT variants, and a KrCERT-linked RAT protocol change expecting the string "n0gyPPx".
KrCERT reported in September 2021 on an operation called ByteTiger targeting South Korean entities and attributed it to Andariel. The reporting introduced the TigerDownloader and TigerRAT names later used in follow-on analysis.
Kaspersky analyzed the same multi-stage intrusion series seen earlier in 2021 and assessed that Andariel, a Lazarus subgroup, was responsible rather than Lazarus broadly. The report also documented ransomware deployment in at least one victim and tied the activity to South Korean victims across several sectors.
Malwarebytes reported a spearphishing campaign using a Korean-language Word document that extracted an HTA from a disguised BMP and dropped AppStore.exe. The loader decrypted an in-memory RAT that communicated with mail.namusoft.kr and jinjinpig.co.kr and supported command execution, payload delivery, file writing, and self-deletion.
ESET disclosed attempts to deploy Lazarus malware in South Korea by abusing compromised websites that used the WIZVERA VeraPort software installation mechanism. The attackers replaced expected downloads with malware signed using stolen or illicit certificates and linked the activity to Operation BookCodes.
QiAnXin described a Lazarus campaign targeting South Korea with politically themed and recruitment-themed lure documents. The attackers used remote template injection to fetch malicious macros that dropped DLL payloads, created a startup LNK for persistence, and contacted elite4print.com for C2.
DHS, FBI, and DoD released a malware analysis report on North Korean government-linked BISTROMATH RAT variants and their CAgent11 controller. The report detailed fake-bitmap loading, XOR-encoded communications, persistence options, and a hard-coded C2 at 159.100.250.231:8080.
KISA’s Operation Bookcodes report states the campaign has targeted South Korea since 2019. The activity used spearphishing, watering holes, compromised web servers, privilege escalation, lateral movement, and Bookcodes malware for remote control and data theft.
Unit 42 reported a 2017 campaign targeting Korean-speaking individuals with malicious Word documents delivered likely by phishing. The documents dropped a UPX-packed implant that established Run-key persistence and used Lazarus-associated fake TLS communications.
Cisco Talos analyzed a targeted campaign using a malicious Hangul Word Processor document impersonating South Korea’s Ministry of Unification. The malware dropped PE files, injected shellcode into wscript.exe, profiled victims, and used compromised websites to exfiltrate data and fetch a further payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 303 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
13 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcethreatray.com
Open sourcesecurelist.com
Open sourceblog.malwarebytes.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourcekrcert.or.kr
Open sourcevblocalhost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.