#GopherRAT

Malware/Tool

2026-01-22 • To the past and beyond: Andariel’s latest arsenal and cyberattacks

GopherRAT is one of three previously undocumented remote-access trojans attributed to Andariel during investigations of attacks in the Republic of Korea. It was discovered alongside StarshellRAT and JelusRAT while researchers examined a compromise involving enterprise resource-planning software and a separate espionage intrusion involving anti-money-laundering documents. Related GopherRAT artifacts were recovered from an Andariel staging server, placing the family within a broader toolset used for persistent access, internal reconnaissance, and follow-on operations against South Korean organizations.

Tagged Reports

« Back