OAK — OnChain Attack Knowledge

Software · OAK-S31 · malware (Windows backdoor / persistent-access remote-access-trojan)

OAK-S31 — TigerRAT

Type
malware (Windows backdoor / persistent-access remote-access-trojan)
Aliases
TigerRAT (the canonical KrCERT/CC + AhnLab naming established in 2022 publications and sustained across continuous Korean-side CTI reporting through 2024–2025); industry-side cross-attribution labels include the broader Andariel cluster naming surface — Silent Chollima (CrowdStrike), Onyx Sleet / Plutonium (Microsoft Threat Intelligence's continuous Andariel-cluster naming), Stonefly (Symantec / Broadcom), DarkSeoul-cohort historical naming for the broader DPRK destructive-and-espionage cluster from which Andariel is the contemporary financially-motivated sub-cluster, and the external Group ID G0138 Andariel Group profile under which TigerRAT activity is documented.
Active
yes — continuous variants tracked through 2024–2025 by KrCERT/CC, AhnLab, Mandiant, Microsoft, and Symantec; the family is a sustained-deployment Andariel-cluster persistence-and-staging tool rather than a campaign-bounded payload, and its operational tempo is paced by Andariel's broader campaign cadence rather than by per-version-release boundaries.
First observed
2022 (KrCERT/CC + AhnLab canonical publications established the family naming in 2022; underlying Andariel-cluster activity using the family is attributed back further by retrospective analysis but the public-record family-naming anchor is 2022).
Used by Groups
OAK-G09 Andariel (primary operator — confirmed-grade institutional attribution per CISA AA22-187A, CISA AA22-321A, the multi-government joint Andariel advisory of July 25, 2024 ([cisa2024andarieladvisory]), and the DOJ Rim Jong Hyok indictment ([doj2024rimjonghyok]); the family is documented as a primary persistence-and-staging tool in Andariel's defence-industrial-base, energy, engineering, and healthcare-sector intrusions, and is a pre-Maui-deployment payload in some campaigns where ransomware-stage deployment is the campaign's terminal phase).
Host platforms
Windows (the only platform observed in public reporting; KrCERT/CC, AhnLab, and Mandiant analyses describe a Windows-only x86 implementation; no macOS or Linux variants documented as of v0.1).
Observed Techniques
OAK-T7.001 (mixer-routed-hop, the principal laundering route for ransom-and-theft proceeds Andariel collects in campaigns where TigerRAT is the staging-and-persistence tool, mirroring the OAK-S25 Maui laundering pattern); OAK-T7.002 (CEX deposit-address layering, post-2022 default for Andariel proceeds); OAK-T8.002 (cross-chain operator continuity, where Andariel-cluster wallet-cluster persistence across TigerRAT-and-successor-payload campaigns is the principal forensic signature used to attribute the family to the broader DPRK constellation).

Description

TigerRAT is a Windows-based backdoor and persistent-access remote-access-trojan attributed to the DPRK-state-sponsored Andariel sub-cluster of the broader Lazarus constellation, deployed across U.S. and Republic-of-Korea defence-industrial-base, energy-sector, engineering-firm, and healthcare-sector targets from at least 2022 forward. The canonical references are the KrCERT/CC and AhnLab 2022 technical publications that first publicly documented the family naming and core capability set ([krcerttigerrat2022], [ahnlabtigerrat2022]); continuous Korean-side and Western-side CTI reporting tracks the family's per-version evolution through 2024–2025, with the multi-government joint Andariel advisory of July 25, 2024 ([cisa2024andarieladvisory]) providing the institutional confirmed-grade U.S.-government attribution anchor.

The family's operational role is persistent access plus operator-driven hands-on-keyboard capability and second-stage staging — a textbook Windows-backdoor functional profile, but operationally distinguished by its embedding in the broader Andariel-cluster intrusion architecture rather than by any single architectural innovation. TigerRAT establishes a persistent C2 channel to operator-controlled infrastructure; supports operator-driven file-system enumeration, file-upload-and-download, process-enumeration-and-control, and live-shell capability; and serves as a staging-payload for operator-side deployment of additional Andariel-cluster tooling including, in some campaigns, the OAK-S25 Maui ransomware. The TigerRAT-to-Maui staging pattern is documented in CISA AA22-187A's incident reconstruction and in the Rim Jong Hyok indictment's campaign-cohort evidence; in healthcare-sector intrusions specifically the pattern is TigerRAT-as-pre-encryption-staging-tool-and-Maui-as-encryption-payload, with the TigerRAT-established foothold providing the operator-supervised manual-deployment surface that Maui's operator-supplied-AES-key architecture (see OAK-S25) requires.

The family's role in the OAK-G09 Andariel monetization chain is the persistent-access-and-staging node that enables the broader Andariel operating model — ransomware proceeds against U.S. and ROK civilian-critical-infrastructure fund follow-on cyber-espionage against U.S. defence-industrial-base, NASA, and energy targets (see OAK-S25 Discussion for the canonical worked example of this pattern). TigerRAT itself does not perform extraction or laundering; the family's OAK-relevance is as the persistence-tooling that enables the ransomware-deployment-and-laundering chain documented at OAK-S25 and the OAK-G09 Group entry.

Observed examples

  • Andariel-attributed defence-industrial-base intrusions (2022–2024). TigerRAT documented as the persistent-access tool in multiple Andariel-cluster intrusions targeting U.S. and ROK DIB, aerospace, energy, engineering, and healthcare verticals per the multi-government joint Andariel advisory of July 25, 2024 ([cisa2024andarieladvisory]); confirmed-grade aggregate attribution.
  • TigerRAT-to-Maui staging pattern (healthcare-sector intrusions, 2021–2023). CISA AA22-187A's incident reconstruction and the Rim Jong Hyok indictment's campaign-cohort evidence document a pattern in which TigerRAT establishes the persistent-access foothold that enables operator-supervised manual-deployment of the Maui ransomware (OAK-S25) — the TigerRAT-as-staging-and-Maui-as-encryption pairing is a documented Andariel-cluster two-stage architecture for healthcare-sector intrusions.
  • KrCERT/CC and AhnLab continuous variant tracking (2022–2025). Korean-side CTI reporting tracks per-version evolution and operator-side variant-rotation cadence; aggregate variant count in the dozens across the tracking window with confirmed-grade attribution to the Andariel cluster.
  • Andariel + Log4Shell exploitation campaigns (2022 onward). CISA AA22-321A and successor advisories document Andariel-cluster exploitation of Log4Shell-class public-facing vulnerabilities as the dominant initial-access vector feeding TigerRAT-staged intrusions across 2022–2024; the public-facing-vuln-exploitation entry vector distinguishes Andariel's tradecraft from the social-engineering-led TraderTraitor (OAK-S08) and BeaverTail / InvisibleFerret (OAK-S29 / S30) campaigns at the OAK-G01 / G08 sub-clusters.
  • OAK on-chain example surface. No OAK examples/ entry exists for TigerRAT-binary specifically as of v0.1; the OAK angle is the Andariel-cluster ransom-and-theft proceeds laundering tail (T7.001, T7.002, T8.002) downstream of TigerRAT-staged intrusions, with the per-incident on-chain forensic record meaningfully cleaner than for commercial-criminal RaaS because of the wallet-cluster reuse pattern documented in OAK-S25 Discussion.

Detection / attribution signals

Defenders should treat TigerRAT detection as a host-layer + network-layer joint problem with the Andariel-cluster intrusion-architecture context as the principal cross-stage forensic framing:

  • Host-layer process-tree fingerprints — Windows-binary signature with the per-version variants documented across KrCERT/CC, AhnLab, Mandiant, and Microsoft reporting; persistence via Run-key, Service registration, or Scheduled Task registration under naming that mimics legitimate Windows-system tooling; characteristic operator-driven file-system enumeration, file-upload-and-download, and process-enumeration-and-control invocations.
  • Pre-deployment tradecraft (Andariel-cluster canonical) — Log4Shell / Log4j-class public-facing-vulnerability exploitation as the dominant initial-access vector through 2022–2024 (CISA AA22-321A and successor advisories); credential theft via custom Andariel-cluster backdoor families (Dtrack, Maui-adjacent loaders); lateral movement via legitimate-administrator tooling and PsExec; Cobalt Strike post-exploitation deployment on some intrusions.
  • Cross-stage payload-chain coupling — TigerRAT-to-Maui staging pattern in healthcare-sector intrusions (the canonical TigerRAT-as-staging-and-Maui-as-encryption pairing); TigerRAT-to-additional-Andariel-tooling staging in DIB / energy / engineering intrusions where the campaign's terminal phase is intelligence-collection rather than encryption-and-extortion.
  • Network-layer telemetry — persistent C2 channel egress to operator-controlled infrastructure with periodic heartbeat-and-tasking pattern; current C2-domain IOCs published in KrCERT/CC and AhnLab reporting and in continuous Western-side CTI-vendor feeds (Mandiant, Microsoft, Symantec).
  • On-chain-layer signatures (the OAK-relevant signal) — Andariel-cluster ransom-and-theft-proceeds wallet-cluster persistence (OAK-T8.002) is the principal forensic-attribution signature for the operator cohort across encryptor-and-staging families; downstream routing has historically run through Sinbad pre-takedown and through Bitcoin-to-other-asset conversions at non-KYC and weak-KYC venues per the OAK-S25 Detection / attribution signals section.
  • CTI vendor coverage — KrCERT/CC (canonical Korean-side reporting and continuous tracking; [krcerttigerrat2022]), AhnLab (canonical Korean-side reporting and continuous tracking; [ahnlabtigerrat2022]), Mandiant (Andariel-cluster tracking and intrusion-set documentation, [mandiantandariel2022]), Microsoft Threat Intelligence (Onyx Sleet / Plutonium naming and continuous tracking, [microsoftonyxsleet2022]), Symantec / Broadcom (Stonefly naming, [symantec2024stonefly]), Recorded Future (Insikt Group Andariel-cluster reporting), CrowdStrike (Silent Chollima naming).

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from KrCERT/CC and AhnLab published indicator lists and from live Western-side CTI-vendor feeds named above.

Citations

  • [krcerttigerrat2022] — KrCERT/CC technical publication on TigerRAT, 2022; canonical Korean-side reference for the family naming and core capability set. (NEW citation — see summary.)
  • [ahnlabtigerrat2022] — AhnLab technical publication on TigerRAT, 2022; canonical Korean-side reference paired with KrCERT/CC. (NEW citation — see summary.)
  • [cisaaa22187a] — CISA / FBI / Treasury joint advisory AA22-187A on Maui ransomware (TigerRAT-to-Maui staging context). (Already cited in OAK-S25 Maui.)
  • [cisaaa22321a] — CISA / FBI joint advisory AA22-321A on Andariel-cluster intrusions (Log4Shell exploitation context). (NEW citation — see summary.)
  • [cisa2024andarieladvisory] — Multi-government joint Andariel advisory, July 25, 2024. (Already in citations.bib per OAK-G09 verification.)
  • [doj2024rimjonghyok] — DOJ unsealed indictment of Rim Jong Hyok, July 25, 2024 (TigerRAT-to-Maui campaign-cohort evidence). (Already in citations.bib per OAK-S25 / OAK-G09.)
  • [mandiantandariel2022] — Mandiant Andariel intrusion-set documentation. (Already in citations.bib per OAK-S25.)
  • [microsoftonyxsleet2022] — Microsoft Threat Intelligence Onyx Sleet / Plutonium analysis. (Already in citations.bib per OAK-S25.)
  • [symantec2024stonefly] — Symantec / Broadcom Stonefly partial-overlap industry name for the Andariel intrusion sub-stream. (Already in citations.bib per OAK-G09 verification.)
  • [chainalysisdprkmaui2024] — Chainalysis tracking of Andariel-attributable ransom-proceeds laundering routes. (Already in citations.bib per OAK-S25.)

Discussion

On lineage. TigerRAT sits within the broader DPRK Andariel-cluster Windows-malware lineage, which is operationally distinct from the macOS-and-cross-platform malware lineage that begins with AppleJeus (OAK-S09) and continues through TraderTraitor (OAK-S08), RustBucket (OAK-S20), KandyKorn (OAK-S19), SwiftLoader (OAK-S21), ObjCShellz (OAK-S22), BeaverTail (OAK-S29), and InvisibleFerret (OAK-S30). Andariel's Windows-malware lineage includes also Dtrack (a long-running Andariel-cluster RAT family from approximately 2018 forward), Maui-adjacent loaders, and the OAK-S25 Maui ransomware itself. TigerRAT's role within this lineage is as a primary 2022-onward persistence-and-staging tool, comparable in operational role to Dtrack but representing a fresh codebase-and-tradecraft generation.

On the Andariel sub-cluster as the operator-cohort context. Andariel is the DPRK-Reconnaissance-General-Bureau-attributed sub-cluster within the broader Lazarus constellation that runs ransomware-and-cyber-espionage against healthcare, defence-industrial-base, and energy targets — distinct on the targeting axis from the OAK-G01 TraderTraitor / APT38 sub-cluster which runs trojanized-trading-app intrusions against crypto-industry firms. TigerRAT's operational embedding in Andariel's intrusion architecture is what gives the family its OAK-relevance: as a standalone Windows backdoor TigerRAT is one of many Windows-backdoor families on the public record; as Andariel's primary persistence-and-staging tool 2022 onward it is the load-bearing tooling for the ransomware-proceeds-fund-espionage operational pattern documented in the OAK-S25 Discussion section.

On the TigerRAT-to-Maui staging pattern. The TigerRAT-as-staging-tool-and-Maui-as-encryption-payload pairing in healthcare-sector intrusions is the canonical worked example of Andariel-cluster two-stage intrusion architecture for the ransomware-deployment phase of the broader campaign. The architectural advantage of the staging design is the same as for the BeaverTail-to-InvisibleFerret pairing at OAK-S29 / S30: lightweight first-stage deployment (TigerRAT, in this case via Log4Shell exploitation) establishes the foothold; operator-side triage selects which compromises to escalate to second-stage deployment (Maui ransomware); second-stage payload's operator-supplied-key architecture (see OAK-S25) requires the operator-supervised manual-deployment surface that the TigerRAT foothold provides.

On the OAK Software-vs-Group split. OAK-S31 (this entry) is the TigerRAT codebase — the specific Andariel-deployed Windows backdoor named by KrCERT/CC and AhnLab. OAK-G09 (already in the v0.1 catalog) is the Andariel operator cluster — the DPRK-RGB-attributed sub-unit. The cardinality is many-to-one in the sense documented at OAK-S25 Discussion: OAK-G09 has multiple OAK-Sxx entries under it (OAK-S25 Maui, OAK-S31 TigerRAT, and likely additional future entries as further Andariel-cluster families are catalogued); each Sxx is a specific codebase and operational role within the cluster's broader tooling inventory.

On ecosystem position. TigerRAT is the persistent-access-and-staging node in the Andariel intrusion architecture; downstream from TigerRAT, the chain runs through Andariel-cluster terminal-phase payloads (OAK-S25 Maui in healthcare-sector campaigns, intelligence-collection-and-exfiltration tooling in DIB / energy / engineering campaigns) and eventually through OAK-T7-Tactic laundering for ransomware-proceeds campaigns. A defender control program targeting TigerRAT at the host-and-network-detection layer compounds with on-chain G09 cluster watchlists at the off-ramp layer; either alone is partial coverage.

Techniques observed (3)

Used by