Andariel 그룹의 국내 솔루션 대상 공격 사례 분석 (SmallTiger)

2024-12-22 Ahnlab Analysis of Andariel attacks targeting South Korean enterprise solutions (SmallTiger)

https://asec.ahnlab.com/ko/85270/

Thumbnail for Andariel 그룹의 국내 솔루션 대상 공격 사례 분석 (SmallTiger)

AhnLab ASEC analyzed Andariel attacks against South Korean enterprise software, including asset-management and document-centralization solutions, that deployed the SmallTiger malware. In asset-management cases, attackers appear to have abused control or update servers to issue malware installation commands, including replacing update programs with SmallTiger and using a keylogger that stored keystrokes in MsMpLog.tmp. The malware was used to enable RDP access, create or hide backdoor accounts with tools such as CreateHiddenAccount, perform reconnaissance commands, and in document-solution cases attempt web-shell deployment from infrastructure also associated with SmallTiger C2 activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.61.148.153 2024-12-22 2024-12-23
IPv4 20.20.100.32 2024-12-22 2024-12-23

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back