logo

Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)

ID: 72668617-6ad9-5237-a01f-b3a1c32e4044

STIX ID: report--72668617-6ad9-5237-a01f-b3a1c32e4044

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-12-22

Date Updated: 2026-04-26

Author: ATCP

...
...

ASEC identified renewed Andariel activity targeting Korean asset-management and document-management solutions, delivering SmallTiger and ModeLoader, using a unique keylogger that stores keystrokes in MsMpLog.tmp, enabling RDP access and creating hidden backdoor accounts, and deploying web shells via outdated Apache Tomcat instances; the report provides IOCs (45.61.148.153, http://45.61.148.153/pizza.jsp, and several MD5 hashes) and recommends patching and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.