Andariel 그룹의 국내 솔루션 대상 공격 사례 분석 (SmallTiger)
2024-12-22 • Ahnlab • Analysis of Andariel attacks targeting South Korean enterprise solutions (SmallTiger) •
AhnLab ASEC analyzed Andariel attacks against South Korean enterprise software, including asset-management and document-centralization solutions, that deployed the SmallTiger malware. In asset-management cases, attackers appear to have abused control or update servers to issue malware installation commands, including replacing update programs with SmallTiger and using a keylogger that stored keystrokes in MsMpLog.tmp. The malware was used to enable RDP access, create or hide backdoor accounts with tools such as CreateHiddenAccount, perform reconnaissance commands, and in document-solution cases attempt web-shell deployment from infrastructure also associated with SmallTiger C2 activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.61.148.153 | 2024-12-22 | 2024-12-23 |
| IPv4 | 20.20.100.32 | 2024-12-22 | 2024-12-23 |