TigerLite

First seen
2021-01-01 00:00:00
Malware type
downloader, rat
Profile updated
2026-07-07 14:49:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr

Context

TigerLite is a TCP downloader. It creates mutexes like "qtrgads32" or "Microsoft32". It uses RC4 with the key "MicrosoftCorporationValidation@#$%^&*()!US" for decryption of its character strings, and a custom algorithm for encryption and decryption of network traffic. It supports from 5 up to 8 commands with the following identifiers: 1111, 1234, 2099/3333, 4444, 8877, 8888, 9876, 9999. The commands mostly perform various types of execution - either of code received from the server, or native Windows commands, with their output collected and sent back to the server. TigerLite is an intermediate step of a multi-stage attack, in which Tiger RAT is usually the next step. This malware was observed in attacks against South Korean entities in H1 2021.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Tigerlite_Auto (yara-rule)

Reports & references

  • ti.qianxin.com — Analysis Of Attacks By Lazarus Using Daewoo Shipyard As Bait (report)
  • Kaspersky — 102811 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tigerlite (report)
  • threatray.com — Establishing The Tigerrat And Tigerdownloader Malware Families (report)
  • threatray.com — Threatray Establishing The Tigerrat And Tigerdownloader Malware Families (report)
  • malwarebytes.com — Lazarus Apt Conceals Malicious Code Within Bmp File To Drop Its Rat (report)

External references