Andariel Hackers Target South Korean Institutes with New Dora RAT Malware
ID: f81bcba1-0500-523d-b7a5-385ec28ea709
STIX ID: report--f81bcba1-0500-523d-b7a5-385ec28ea709
Feed Name: The Hacker News
Andariel, a North Korea-linked APT, has been observed deploying a new Golang backdoor dubbed Dora RAT—alongside Nestdoor variants, a keylogger, an information stealer, and a SOCKS5 proxy—against educational, manufacturing, and construction targets in South Korea by abusing an outdated Apache Tomcat server; some Dora RAT binaries were distributed with a valid UK code-signing certificate and the activity ties into prior Andariel/Lazarus campaigns involving SmallTiger and DurianBeacon.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
