SmallTiger Malware Used in Attacks Against South Korean Businesses (Kimsuky and Andariel)
ID: 04dde797-029d-5908-8093-c675508b8761
STIX ID: report--04dde797-029d-5908-8093-c675508b8761
Feed Name: ASEC
ASEC observed a sustained campaign (Nov 2023–May 2024) targeting South Korean defense contractors, automotive suppliers, and semiconductor firms that delivered DurianBeacon and later the SmallTiger downloader. Attackers abused internal software updaters and alternate data streams, used mshta/rundll32, performed credential dumping (ProcDump, Mimikatz) and browser password theft, and hosted payloads on C2 infrastructure and GitHub; the report includes file hashes, URLs, behavior detections, and links to Kimsuky/Andariel activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
