#LilithRAT
Malware/Tool
2023-11-10 • 자산 관리 프로그램을 악용한 공격 정황 포착 (Andariel 그룹)
Lilith RAT is an open-source remote-access Trojan originally written in C++ and published on GitHub. It supports remote command execution, persistence, and self-deletion. Andariel used a modified build whose binary encrypted many strings to evade file-based detection while retaining strings shared with the public source code. Another North Korea-linked campaign delivered an AutoIt reimplementation through the CURKON malicious shortcut; that version created a reverse shell, accepted commands over a hardcoded socket, executed commands through cmd or PowerShell, and established persistence through scheduled tasks or the Windows Startup folder.
-
3
Tagged Reports
-
2
Unique Authors
-
287
Active Days