Netskope Threat Labs

TigerRAT

ATP Sandbox Adv. HeuristicsAVNetskope IPS

TigerRAT is a third stage backdoor documented in Kaspersky's reporting on the Andariel group's evolution toward ransomware attacks in South Korea. Its payloads disguise themselves with Internet Explorer and Google Chrome icons and filenames, decrypt an embedded payload at runtime with an XOR key, and execute the result in memory after checking for sandbox environments. Researchers noted code overlap with the PEBBLEDASH family, which researchers attribute to Lazarus and LABYRINTH CHOLLIMA.

First seen
October 2022
Last seen
October 2026
Tigerrat
Alert Name
DeepScan:Generic.TigerRAT.A.5882162D
DeepScan:Generic.TigerRAT.A.BEF02308
Dump:Generic.TigerRAT.A.5882162D
Dump:Generic.TigerRAT.A.BEF02308
Generic.TigerRAT.A.05993048
Generic.TigerRAT.A.08848DE8
Generic.TigerRAT.A.13FD9B34
Generic.TigerRAT.A.14EF8D81
Generic.TigerRAT.A.376C9488
Generic.TigerRAT.A.7A3D3503