Description
TigerRAT is a third stage backdoor documented in Kaspersky's reporting on the Andariel group's evolution toward ransomware attacks in South Korea. Its payloads disguise themselves with Internet Explorer and Google Chrome icons and filenames, decrypt an embedded payload at runtime with an XOR key, and execute the result in memory after checking for sandbox environments. Researchers noted code overlap with the PEBBLEDASH family, which researchers attribute to Lazarus and LABYRINTH CHOLLIMA.
Stats
- First seen
- October 2022
- Last seen
- October 2026
Also known as
Tigerrat
Alert name variants
| Alert Name |
|---|
| DeepScan:Generic.TigerRAT.A.5882162D |
| DeepScan:Generic.TigerRAT.A.BEF02308 |
| Dump:Generic.TigerRAT.A.5882162D |
| Dump:Generic.TigerRAT.A.BEF02308 |
| Generic.TigerRAT.A.05993048 |
| Generic.TigerRAT.A.08848DE8 |
| Generic.TigerRAT.A.13FD9B34 |
| Generic.TigerRAT.A.14EF8D81 |
| Generic.TigerRAT.A.376C9488 |
| Generic.TigerRAT.A.7A3D3503 |