#DoraRAT
Malware/Tool
2024-05-16 • Dora RAT을 이용한 국내 기업 대상 APT 공격 사례 분석 (Andariel 그룹)
DoraRAT is a Windows remote-access trojan deployed by Andariel against South Korean construction and machinery organizations. The campaign exploited vulnerabilities in security software and replaced an update file with a malicious payload. Vulnerable clients then accepted and executed the substituted file as a legitimate software update, allowing the attackers to cross the initial execution boundary through a trusted process. After compromise, an attacker-controlled command-and-control server delivered DoraRAT to provide remote access within the targeted environment.
-
3
Tagged Reports
-
2
Unique Authors
-
82
Active Days