Software · OAK-S31 · malware (Windows backdoor / persistent-access remote-access-trojan)
OAK-S31 — TigerRAT
Description
TigerRAT is a Windows-based backdoor and persistent-access remote-access-trojan attributed to the DPRK-state-sponsored Andariel sub-cluster of the broader Lazarus constellation, deployed across U.S. and Republic-of-Korea defence-industrial-base, energy-sector, engineering-firm, and healthcare-sector targets from at least 2022 forward. The canonical references are the KrCERT/CC and AhnLab 2022 technical publications that first publicly documented the family naming and core capability set ([krcerttigerrat2022], [ahnlabtigerrat2022]); continuous Korean-side and Western-side CTI reporting tracks the family's per-version evolution through 2024–2025, with the multi-government joint Andariel advisory of July 25, 2024 ([cisa2024andarieladvisory]) providing the institutional confirmed-grade U.S.-government attribution anchor.
The family's operational role is persistent access plus operator-driven hands-on-keyboard capability and second-stage staging — a textbook Windows-backdoor functional profile, but operationally distinguished by its embedding in the broader Andariel-cluster intrusion architecture rather than by any single architectural innovation. TigerRAT establishes a persistent C2 channel to operator-controlled infrastructure; supports operator-driven file-system enumeration, file-upload-and-download, process-enumeration-and-control, and live-shell capability; and serves as a staging-payload for operator-side deployment of additional Andariel-cluster tooling including, in some campaigns, the OAK-S25 Maui ransomware. The TigerRAT-to-Maui staging pattern is documented in CISA AA22-187A's incident reconstruction and in the Rim Jong Hyok indictment's campaign-cohort evidence; in healthcare-sector intrusions specifically the pattern is TigerRAT-as-pre-encryption-staging-tool-and-Maui-as-encryption-payload, with the TigerRAT-established foothold providing the operator-supervised manual-deployment surface that Maui's operator-supplied-AES-key architecture (see OAK-S25) requires.
The family's role in the OAK-G09 Andariel monetization chain is the persistent-access-and-staging node that enables the broader Andariel operating model — ransomware proceeds against U.S. and ROK civilian-critical-infrastructure fund follow-on cyber-espionage against U.S. defence-industrial-base, NASA, and energy targets (see OAK-S25 Discussion for the canonical worked example of this pattern). TigerRAT itself does not perform extraction or laundering; the family's OAK-relevance is as the persistence-tooling that enables the ransomware-deployment-and-laundering chain documented at OAK-S25 and the OAK-G09 Group entry.
Observed examples
- Andariel-attributed defence-industrial-base intrusions (2022–2024). TigerRAT documented as the persistent-access tool in multiple Andariel-cluster intrusions targeting U.S. and ROK DIB, aerospace, energy, engineering, and healthcare verticals per the multi-government joint Andariel advisory of July 25, 2024 (
[cisa2024andarieladvisory]); confirmed-grade aggregate attribution. - TigerRAT-to-Maui staging pattern (healthcare-sector intrusions, 2021–2023). CISA AA22-187A's incident reconstruction and the Rim Jong Hyok indictment's campaign-cohort evidence document a pattern in which TigerRAT establishes the persistent-access foothold that enables operator-supervised manual-deployment of the Maui ransomware (OAK-S25) — the TigerRAT-as-staging-and-Maui-as-encryption pairing is a documented Andariel-cluster two-stage architecture for healthcare-sector intrusions.
- KrCERT/CC and AhnLab continuous variant tracking (2022–2025). Korean-side CTI reporting tracks per-version evolution and operator-side variant-rotation cadence; aggregate variant count in the dozens across the tracking window with confirmed-grade attribution to the Andariel cluster.
- Andariel + Log4Shell exploitation campaigns (2022 onward). CISA AA22-321A and successor advisories document Andariel-cluster exploitation of Log4Shell-class public-facing vulnerabilities as the dominant initial-access vector feeding TigerRAT-staged intrusions across 2022–2024; the public-facing-vuln-exploitation entry vector distinguishes Andariel's tradecraft from the social-engineering-led TraderTraitor (OAK-S08) and BeaverTail / InvisibleFerret (OAK-S29 / S30) campaigns at the OAK-G01 / G08 sub-clusters.
- OAK on-chain example surface. No OAK
examples/entry exists for TigerRAT-binary specifically as of v0.1; the OAK angle is the Andariel-cluster ransom-and-theft proceeds laundering tail (T7.001, T7.002, T8.002) downstream of TigerRAT-staged intrusions, with the per-incident on-chain forensic record meaningfully cleaner than for commercial-criminal RaaS because of the wallet-cluster reuse pattern documented in OAK-S25 Discussion.
Detection / attribution signals
Defenders should treat TigerRAT detection as a host-layer + network-layer joint problem with the Andariel-cluster intrusion-architecture context as the principal cross-stage forensic framing:
- Host-layer process-tree fingerprints — Windows-binary signature with the per-version variants documented across KrCERT/CC, AhnLab, Mandiant, and Microsoft reporting; persistence via Run-key, Service registration, or Scheduled Task registration under naming that mimics legitimate Windows-system tooling; characteristic operator-driven file-system enumeration, file-upload-and-download, and process-enumeration-and-control invocations.
- Pre-deployment tradecraft (Andariel-cluster canonical) — Log4Shell / Log4j-class public-facing-vulnerability exploitation as the dominant initial-access vector through 2022–2024 (CISA AA22-321A and successor advisories); credential theft via custom Andariel-cluster backdoor families (Dtrack, Maui-adjacent loaders); lateral movement via legitimate-administrator tooling and PsExec; Cobalt Strike post-exploitation deployment on some intrusions.
- Cross-stage payload-chain coupling — TigerRAT-to-Maui staging pattern in healthcare-sector intrusions (the canonical TigerRAT-as-staging-and-Maui-as-encryption pairing); TigerRAT-to-additional-Andariel-tooling staging in DIB / energy / engineering intrusions where the campaign's terminal phase is intelligence-collection rather than encryption-and-extortion.
- Network-layer telemetry — persistent C2 channel egress to operator-controlled infrastructure with periodic heartbeat-and-tasking pattern; current C2-domain IOCs published in KrCERT/CC and AhnLab reporting and in continuous Western-side CTI-vendor feeds (Mandiant, Microsoft, Symantec).
- On-chain-layer signatures (the OAK-relevant signal) — Andariel-cluster ransom-and-theft-proceeds wallet-cluster persistence (OAK-T8.002) is the principal forensic-attribution signature for the operator cohort across encryptor-and-staging families; downstream routing has historically run through Sinbad pre-takedown and through Bitcoin-to-other-asset conversions at non-KYC and weak-KYC venues per the OAK-S25 Detection / attribution signals section.
- CTI vendor coverage — KrCERT/CC (canonical Korean-side reporting and continuous tracking;
[krcerttigerrat2022]), AhnLab (canonical Korean-side reporting and continuous tracking;[ahnlabtigerrat2022]), Mandiant (Andariel-cluster tracking and intrusion-set documentation,[mandiantandariel2022]), Microsoft Threat Intelligence (Onyx Sleet / Plutonium naming and continuous tracking,[microsoftonyxsleet2022]), Symantec / Broadcom (Stonefly naming,[symantec2024stonefly]), Recorded Future (Insikt Group Andariel-cluster reporting), CrowdStrike (Silent Chollima naming).
Note: omit specific file hashes from this entry. Defenders should consume current IOCs from KrCERT/CC and AhnLab published indicator lists and from live Western-side CTI-vendor feeds named above.
Citations
[krcerttigerrat2022]— KrCERT/CC technical publication on TigerRAT, 2022; canonical Korean-side reference for the family naming and core capability set. (NEW citation — see summary.)[ahnlabtigerrat2022]— AhnLab technical publication on TigerRAT, 2022; canonical Korean-side reference paired with KrCERT/CC. (NEW citation — see summary.)[cisaaa22187a]— CISA / FBI / Treasury joint advisory AA22-187A on Maui ransomware (TigerRAT-to-Maui staging context). (Already cited in OAK-S25 Maui.)[cisaaa22321a]— CISA / FBI joint advisory AA22-321A on Andariel-cluster intrusions (Log4Shell exploitation context). (NEW citation — see summary.)[cisa2024andarieladvisory]— Multi-government joint Andariel advisory, July 25, 2024. (Already in citations.bib per OAK-G09 verification.)[doj2024rimjonghyok]— DOJ unsealed indictment of Rim Jong Hyok, July 25, 2024 (TigerRAT-to-Maui campaign-cohort evidence). (Already in citations.bib per OAK-S25 / OAK-G09.)[mandiantandariel2022]— Mandiant Andariel intrusion-set documentation. (Already in citations.bib per OAK-S25.)[microsoftonyxsleet2022]— Microsoft Threat Intelligence Onyx Sleet / Plutonium analysis. (Already in citations.bib per OAK-S25.)[symantec2024stonefly]— Symantec / Broadcom Stonefly partial-overlap industry name for the Andariel intrusion sub-stream. (Already in citations.bib per OAK-G09 verification.)[chainalysisdprkmaui2024]— Chainalysis tracking of Andariel-attributable ransom-proceeds laundering routes. (Already in citations.bib per OAK-S25.)
Discussion
On lineage. TigerRAT sits within the broader DPRK Andariel-cluster Windows-malware lineage, which is operationally distinct from the macOS-and-cross-platform malware lineage that begins with AppleJeus (OAK-S09) and continues through TraderTraitor (OAK-S08), RustBucket (OAK-S20), KandyKorn (OAK-S19), SwiftLoader (OAK-S21), ObjCShellz (OAK-S22), BeaverTail (OAK-S29), and InvisibleFerret (OAK-S30). Andariel's Windows-malware lineage includes also Dtrack (a long-running Andariel-cluster RAT family from approximately 2018 forward), Maui-adjacent loaders, and the OAK-S25 Maui ransomware itself. TigerRAT's role within this lineage is as a primary 2022-onward persistence-and-staging tool, comparable in operational role to Dtrack but representing a fresh codebase-and-tradecraft generation.
On the Andariel sub-cluster as the operator-cohort context. Andariel is the DPRK-Reconnaissance-General-Bureau-attributed sub-cluster within the broader Lazarus constellation that runs ransomware-and-cyber-espionage against healthcare, defence-industrial-base, and energy targets — distinct on the targeting axis from the OAK-G01 TraderTraitor / APT38 sub-cluster which runs trojanized-trading-app intrusions against crypto-industry firms. TigerRAT's operational embedding in Andariel's intrusion architecture is what gives the family its OAK-relevance: as a standalone Windows backdoor TigerRAT is one of many Windows-backdoor families on the public record; as Andariel's primary persistence-and-staging tool 2022 onward it is the load-bearing tooling for the ransomware-proceeds-fund-espionage operational pattern documented in the OAK-S25 Discussion section.
On the TigerRAT-to-Maui staging pattern. The TigerRAT-as-staging-tool-and-Maui-as-encryption-payload pairing in healthcare-sector intrusions is the canonical worked example of Andariel-cluster two-stage intrusion architecture for the ransomware-deployment phase of the broader campaign. The architectural advantage of the staging design is the same as for the BeaverTail-to-InvisibleFerret pairing at OAK-S29 / S30: lightweight first-stage deployment (TigerRAT, in this case via Log4Shell exploitation) establishes the foothold; operator-side triage selects which compromises to escalate to second-stage deployment (Maui ransomware); second-stage payload's operator-supplied-key architecture (see OAK-S25) requires the operator-supervised manual-deployment surface that the TigerRAT foothold provides.
On the OAK Software-vs-Group split. OAK-S31 (this entry) is the TigerRAT codebase — the specific Andariel-deployed Windows backdoor named by KrCERT/CC and AhnLab. OAK-G09 (already in the v0.1 catalog) is the Andariel operator cluster — the DPRK-RGB-attributed sub-unit. The cardinality is many-to-one in the sense documented at OAK-S25 Discussion: OAK-G09 has multiple OAK-Sxx entries under it (OAK-S25 Maui, OAK-S31 TigerRAT, and likely additional future entries as further Andariel-cluster families are catalogued); each Sxx is a specific codebase and operational role within the cluster's broader tooling inventory.
On ecosystem position. TigerRAT is the persistent-access-and-staging node in the Andariel intrusion architecture; downstream from TigerRAT, the chain runs through Andariel-cluster terminal-phase payloads (OAK-S25 Maui in healthcare-sector campaigns, intelligence-collection-and-exfiltration tooling in DIB / energy / engineering campaigns) and eventually through OAK-T7-Tactic laundering for ransomware-proceeds campaigns. A defender control program targeting TigerRAT at the host-and-network-detection layer compounds with on-chain G09 cluster watchlists at the off-ramp layer; either alone is partial coverage.