Andariel Hackers Target South Korean Institutes with New Dora RAT Malware
The newly discovered Golang-based backdoor known as Dora RAT has been used by the North Korea-affiliated threat actor Andariel in its assaults against South Korean educational institutions, manufacturing companies, and construction companies.
The attacks made use of proxy tools, infostealer, and keylogger in addition to the backdoor, according to a study released last week by the AhnLab Security Intelligence Center (ASEC). These malware variants were most likely employed by the threat actor to take over and steal data from the compromised systems.
The South Korean cybersecurity company said that the attacks are typified by the malware being disseminated using a vulnerable Apache Tomcat server. The system in question was running the 2013 version of Apache Tomcat, which left it open t...

