Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 18:29:21 UTC Home > List all groups > List all tools > List all groups using tool TigerRAT Tool: TigerRAT Names TigerRAT Tiger RAT Category Malware Type Backdoor Description (Talos) The second implant hosted on MagicRAT's C2 is a remote access trojan (RAT) known as TigerRAT. TigerRAT is an implant disclosed in 2021 by KISA and KRCERT as part of 'Operation ByteTiger'' detailing TigerRAT and its downloader 'TigerDownloader.' This implant consists of several RAT capabilities, ranging from arbitrary command execution to file management. Information Malpedia Last change to this tool card: 28 December 2022 Download this tool card in JSON format All groups using tool TigerRAT Changed Name Country Observed APT groups   Lazarus Group, Hidden Cobra, Labyrinth Chollima 2007-May 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1632dcd1-575f-49a9-960e-20b930df5396 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1632dcd1-575f-49a9-960e-20b930df5396 Page 1 of 1