#Nestdoor

Malware/Tool

2024-05-16 • Dora RAT을 이용한 국내 기업 대상 APT 공격 사례 분석 (Andariel 그룹)

Nestdoor is a C++ remote access trojan and backdoor observed since at least May 2022 in attacks attributed to Andariel. It receives attacker commands to control infected systems and has appeared alongside web shells, keyloggers, information stealers, proxy tools, and TigerRAT. Reported capabilities for the associated RAT set include file upload and download, reverse shell access, command execution, keylogging, clipboard logging, and proxying, with binary obfuscation used to hinder analysis. One documented delivery context involved attacks on an outdated Apache Tomcat web server to install backdoors and proxy tools; related cases exploited VMware Horizon's Log4Shell vulnerability. Targeted South Korean organizations included manufacturing, construction, and education entities.

Tagged Reports

« Back