logo

Andariel Hackers Target South Korean Institutes with New Dora RAT Malware

ID: f81bcba1-0500-523d-b7a5-385ec28ea709

STIX ID: report--f81bcba1-0500-523d-b7a5-385ec28ea709

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-03

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Andariel, a North Korea-linked APT, has been observed deploying a new Golang backdoor dubbed Dora RAT—alongside Nestdoor variants, a keylogger, an information stealer, and a SOCKS5 proxy—against educational, manufacturing, and construction targets in South Korea by abusing an outdated Apache Tomcat server; some Dora RAT binaries were distributed with a valid UK code-signing certificate and the activity ties into prior Andariel/Lazarus campaigns involving SmallTiger and DurianBeacon.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.