국내 기업 대상 공격에 사용 중인 SmallTiger 악성코드 (Kimsuky, Andariel 그룹)
2024-05-27 • Ahnlab • SmallTiger malware used in attacks against domestic companies by Kimsuky and Andariel-linked activity •
AhnLab ASEC reports attacks on South Korean defense, automotive-parts, and semiconductor organizations using the SmallTiger malware family. The activity shows overlap with Kimsuky tradecraft but also includes enterprise software-update abuse and DurianBeacon, a backdoor previously associated with Andariel, making the campaign important for tracking North Korean intrusion clusters and lateral-movement tooling.
Indicators of Compromise
Related Actors
Related Reports
Shares tags: Andariel, Kimsuky, DurianBeacon • Shares 49 IOCs • Same author: Ahnlab • Published within a month
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Same author: Ahnlab • Published within a month
Shares tag: Kimsuky • Same author: Ahnlab • Published within a month
Shares tag: Andariel • Same author: Ahnlab • Published within a week
Shares tag: Kimsuky • Same author: Ahnlab • Published within a week