TinyMet
Aliases: TiniMet
- First seen
- 2017-03-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-13 08:45:05
- Profile updated
- 2026-07-07 12:45:35
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
TinyMet is a lightweight meterpreter stager, often used for establishing remote access on compromised systems. It is known for being a minimalistic and efficient loader for more complex payloads.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Tinymet_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Niagara (report)
- telekom.com — Cybersecurity Ta505 S Box Of Chocolate 597672 (report)
- securityintelligence.com — Ta505 Continues To Infect Networks With Sdbbot Rat (report)
- fsec.or.kr — 2297.Do (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- flashpoint-intel.com — Fin7 Revisited: Inside Astra Panel And Sqlrat Malware (report)
- blueliv.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
- outpost24.com — Using Qiling Framework To Unpack Ta505 Packed Samples (report)
- CrowdStrike — How Falcon Complete Stopped A Solarwinds Serv U Exploit Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tinymet (report)
- twitter.com — 1273292957429510150 (report)
- github.com — Tinymet (report)
- CrowdStrike — How Falcon Complete Stopped A Big Game Hunting Ransomware Attack (report)