#AndarLoader

Malware/Tool

2023-08-22 • Andariel 그룹의 새로운 공격 활동 분석

AndarLoader is a downloader used in Andariel operations against Windows systems. It connects to a command-and-control server, retrieves executable data such as .NET assemblies, and runs the downloaded code in memory; supported commands also allow a downloaded .NET method to run or the loader to delete itself and terminate. Observed versions were obfuscated with Dotfuscator or KoiVM and used the string “sslClient” during C2 communication. Korean asset-management software was abused to install it during lateral movement.

Tagged Reports

« Back