Tiger RAT

First seen
2021-07-15 00:00:00
Malware type
backdoor, rat
Family
Malware family
Last IoC activity
2026-05-07 05:22:41
Profile updated
2026-07-07 14:44:38

Targeted industries: government-and-public-sector

Targeted regions: country_code:kr

Context

This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware". The third stage payload was created via the second stage payload, is interactively executed in the operation and exists in both x64 and x86 versions. Most of them use Internet Explorer or Google Chrome icons and corresponding file names to disguise themselves as legitimate internet browsers. The malware decrypts the embedded payload at runtime. It uses an embedded 16-byte XOR key to decrypt the base64 encoded payload. The decrypted payload is another portable executable file that runs in memory. Before getting decrypted with a hardcoded XOR key, the backdoor also checks for sandbox environment. The backdoor has some code overlap with a know malware family PEBBLEDASH, attributed to Lazarus/LABYRINTH CHOLLIMA.

Detection coverage

  • 2 YARA rules

Detection rules

  • SIGNATURE_BASE_MAL_APT_NK_Andariel_Tigerrat_Crowdsourced_Rule (yara-rule)
  • SIGNATURE_BASE_MAL_APT_NK_WIN_Tiger_RAT_Auto (yara-rule)

Reports & references

  • asec.ahnlab.com — 56256 (report)
  • asec.ahnlab.com — 56405 (report)
  • Kaspersky — 102811 (report)
  • asec.ahnlab.com — Lazarus %Ea%B7%B8%Eb%A3%B9%Ec%9D%98 Nukesped %Ec%95%85%Ec%84%B1%Ec%Bd%94%Eb%93%9C %Eb%B6%84%Ec%84%9D %Eb%B3%B4%Ea%B3%A0%Ec%84%9C (report)
  • media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
  • asec.ahnlab.com — 58215 (report)
  • attackiq.com — Emulating The Highly Sophisticated North Korean Adversary Lazarus Group (report)
  • Cisco Talos — Lazarus Magicrat (report)
  • threatray.com — Establishing The Tigerrat And Tigerdownloader Malware Families (report)
  • threatray.com — Threatray Establishing The Tigerrat And Tigerdownloader Malware Families (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tiger Rat (report)
  • blogs.vmware.com — Tigerrat Advanced Adversaries On The Prowl (report)
  • krcert.or.kr — Filedownload.Do (report)
  • brighttalk.com — 493986 (report)

External references