Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)

2024-12-23 Ahnlab

https://asec.ahnlab.com/en/85400/

Thumbnail for Analysis of Attack Cases Against Korean Solutions by the Andariel Group (SmallTiger)

AhnLab reports that Andariel continued attacks against South Korean enterprise software in late 2024, primarily installing SmallTiger through compromised or vulnerable management solutions. The cases include long-running exploitation of asset management systems, possible takeover of exposed update servers through brute-force or dictionary attacks, replacement of update programs with SmallTiger, and use of a keylogger that writes keystrokes to MsMpLog.tmp. SmallTiger was also used to enable RDP, while the open-source CreateHiddenAccount tool created a concealed backdoor account for persistence. A separate document-management case involved outdated Apache Tomcat servers, basic host reconnaissance commands, Advanced Port Scanner, and a suspected web shell downloaded from 45.61.148[.]153, which AhnLab also identifies as SmallTiger C2 infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.61.148.153 2024-12-22 2024-12-23
IPv4 20.20.100.32 2024-12-22 2024-12-23

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back