Microsoft Reveals Andariel's New Dora RAT and Decade-Long Malware Arsenal Targeting Aerospace and Defence

On the same day the US DOJ indicted North Korean operative Rim Jong Hyok, Microsoft Threat Intelligence published a comprehensive profile of Onyx Sleet — its name for Andariel — cataloguing a decade of custom tooling, a newly identified malware family, and confirmed aerospace and defence compromises spanning October 2023 through June 2024.

Dora RAT: New Go-Based Backdoor

The disclosure revealed Dora RAT, a previously undocumented backdoor written in Go, deployed against South Korean educational institutions, construction companies, and manufacturing organisations in May 2024. It joins a deep bench including LightHand, BlackRAT, and the long-running DTrack RAT — active from September 2019 through at least January 2024.

DTrack is typically delivered via CVE-2021-44228 (Log4j 2), with payloads signed using invalid certificates impersonating legitimate software — including a fake Tableau Software certificate — to evade detection. Between October 2023 and June 2024, a campaign compromised multiple aerospace and defence organisations exploiting the same Log4j flaw alongside custom exploits targeting South Korean endpoint management and EDR software.

DOJ Indictment and FBI Collaboration

Microsoft confirmed direct collaboration with the FBI in tracking Onyx Sleet. Indictment targets included two US Air Force bases and NASA's Office of Inspector General, with over 30 gigabytes of data exfiltrated in at least one case. Laundered ransom proceeds funded VPS infrastructure used in further exfiltration operations.

"Onyx Sleet's ability to develop a spectrum of tools to launch its tried-and-true attack chain makes it a persistent threat, particularly to targets of interest to North Korean intelligence, like organizations in the defense, engineering, and energy sectors," Microsoft stated.

Organisations in these sectors should treat Sliver C2 activity, Ngrok tunnelling, or DTrack indicators as high-priority signals requiring immediate escalation and containment.

Detection coverage

Read the full analysis on IntelFusions