POOLRAT

Aliases: SIMPLESEA, SIMPLETEA

First seen
2020-04-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:10:46

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:us country_code:ru country_code:cn

Context

POOLRAT, also known as SIMPLESEA and SIMPLETEA, is a remote access trojan known for its use in cyber espionage campaigns. It enables attackers to gain unauthorized access and control over compromised systems, targeting primarily government and financial institutions.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Multi_POOLRAT (yara-rule)
  • SIGNATURE_BASE_SUSP_NK_MAL_M_Hunting_POOLRAT (yara-rule)

Reports & references

  • Mandiant — 3Cx Software Supply Chain Compromise (report)
  • ESET — Linux Malware Strengthens Links Lazarus 3Cx Supply Chain Attack (report)
  • acronis.com — Acronis Tru Alliance Huntio Hunting Dprk Threats New Global Lazarus And Kimsuky Campaigns (report)
  • virusbulletin.com — Lazarus Campaigns And Backdoors In 2022 2023 (report)
  • Broadcom/Symantec — Lazarus North Korea Indictment (report)
  • CISA — Ar21 048E (report)
  • malpedia.caad.fkie.fraunhofer.de — Osx.Poolrat (report)
  • 3cx.com — Mandiant Security Update2 (report)

External references