Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)
2024-12-23 • Ahnlab •
AhnLab reports that Andariel continued attacks against South Korean enterprise software in late 2024, primarily installing SmallTiger through compromised or vulnerable management solutions. The cases include long-running exploitation of asset management systems, possible takeover of exposed update servers through brute-force or dictionary attacks, replacement of update programs with SmallTiger, and use of a keylogger that writes keystrokes to MsMpLog.tmp. SmallTiger was also used to enable RDP, while the open-source CreateHiddenAccount tool created a concealed backdoor account for persistence. A separate document-management case involved outdated Apache Tomcat servers, basic host reconnaissance commands, Advanced Port Scanner, and a suspected web shell downloaded from 45.61.148[.]153, which AhnLab also identifies as SmallTiger C2 infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.61.148.153 | 2024-12-22 | 2024-12-23 |
| IPv4 | 20.20.100.32 | 2024-12-22 | 2024-12-23 |