POOLRAT
Aliases: SIMPLESEA, SIMPLETEA
- First seen
- 2020-04-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:10:46
Targeted industries: government-and-public-sector financial-services
Targeted regions: country_code:us country_code:ru country_code:cn
Context
POOLRAT, also known as SIMPLESEA and SIMPLETEA, is a remote access trojan known for its use in cyber espionage campaigns. It enables attackers to gain unauthorized access and control over compromised systems, targeting primarily government and financial institutions.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Multi_POOLRAT (yara-rule)
- SIGNATURE_BASE_SUSP_NK_MAL_M_Hunting_POOLRAT (yara-rule)
Reports & references
- Mandiant — 3Cx Software Supply Chain Compromise (report)
- ESET — Linux Malware Strengthens Links Lazarus 3Cx Supply Chain Attack (report)
- acronis.com — Acronis Tru Alliance Huntio Hunting Dprk Threats New Global Lazarus And Kimsuky Campaigns (report)
- virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
- Broadcom/Symantec — Lazarus North Korea Indictment (report)
- CISA — Ar21 048E (report)
- malpedia.caad.fkie.fraunhofer.de — Osx.Poolrat (report)
- 3cx.com — Mandiant Security Update2 (report)