#POOLRAT
Malware/Tool
2024-09-09 • Threat Assessment: North Korean Threat Groups
POOLRAT is a Lazarus-linked remote-access trojan used in North Korean post-exploitation activity. The family is associated with secure deletion behavior that repeatedly overwrites files before removing them, reducing the chance that deleted artifacts can be recovered during forensic analysis. PondRAT and newer related tooling have exhibited the same anti-forensic capability. POOLRAT therefore combines remote-access use with deliberate artifact destruction, supporting operators who need to maintain control of a compromised environment while limiting traces left behind during or after an intrusion.
-
3
Tagged Reports
-
2
Unique Authors
-
628
Active Days