ScoringMathTea
- First seen
- 2022-11-01 00:00:00
- Malware type
- rat, dropper
- Family
- Malware family
- Profile updated
- 2026-07-07 14:51:13
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:kr
Context
According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine. Its first appearance dates to late 2022, when its dropper was uploaded to VirusTotal. Soon after, it was seen in the wild, and since then in multiple attacks attributed to Lazarus’ Operation DreamJob campaigns, which makes it the attacker’s payload of choice for already three years. It uses compromised servers for C&C communication, with the server part usually stored under the WordPress folder containing design templates or plugins.
Reports & references
- ESET — Gotta Fly Lazarus Targets Uav Sector (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Scoring Math Tea (report)
- 0x0d4y.blog — Arsenal Analysis Of A Nation State Actor An In Depth Look At Lazarus Scoringmathtea (report)