#DoraRAT

Malware/Tool

2024-05-16 • Dora RAT을 이용한 국내 기업 대상 APT 공격 사례 분석 (Andariel 그룹)

DoraRAT is a Windows remote-access trojan deployed by Andariel against South Korean construction and machinery organizations. The campaign exploited vulnerabilities in security software and replaced an update file with a malicious payload. Vulnerable clients then accepted and executed the substituted file as a legitimate software update, allowing the attackers to cross the initial execution boundary through a trusted process. After compromise, an attacker-controlled command-and-control server delivered DoraRAT to provide remote access within the targeted environment.

Tagged Reports

« Back