Alpha Cyber

Unmasking Dora RAT: Defend Against Andariel APT with Effective Infrastructure Mapping

In the ever evolving landscape of cybersecurity, threat actors are continuously adapting and refining their tactics to bypass traditional defenses.

Alpha Cyber Research4 min readupdated 1 Apr 2026
Andariel Hacking Group

Uncovering the Hidden Threat: Investigating Dora RAT Used by Andariel APT and Strengthening Your Infrastructure with Threat Mapping

In the ever evolving landscape of cybersecurity, threat actors are continuously adapting and refining their tactics to bypass traditional defenses. One particularly concerning threat comes from the Andariel APT, an advanced persistent threat group associated with North Korea. A critical component of Andariel’s toolkit is the Dora RAT (Remote Access Trojan), a stealthy and powerful malware designed to infiltrate networks, steal sensitive data, and maintain longterm access to compromised systems.

As cyberattacks grow in complexity and frequency, it’s essential to have the right tools and strategies in place to protect your infrastructure. One highly effective way to defend against threats like Dora RAT is through Infrastructure Mapping. By understanding your network’s layout and using threat intelligence to track potential attack vectors, you can detect and neutralize threats before they cause significant damage.

In this post, we’ll explore the infrastructure map of Dora RAT used by Andariel APT, provide insights on how these attacks unfold, and introduce steps for fortifying your defenses using threat detection tools. Additionally, we’ll provide a comprehensive list of Indicators of Compromise (IOCs) associated with Dora RAT that you can use to block malicious activity and improve your network security posture.

Understanding the Dora RAT and Andariel APT

The Andariel APT group is known for its sophisticated attacks targeting governments, defense contractors, and critical infrastructure worldwide. Their Dora RAT is a highly effective backdoor Trojan that allows attackers to gain remote access to infected systems, exfiltrate data, and move laterally within networks. Once deployed, Dora RAT operates in stealth, avoiding detection by conventional security tools.

Andariel’s campaign often involves multistage attacks, including:

Initial phishing or social engineering attacks to gain access.
Exploiting vulnerabilities in systems (e.g., CVE-2021-44228) to install malware.
Maintaining persistence through backdoors, like Dora RAT, for long term access.

Once an organization is compromised, the attackers can use Dora RAT to infiltrate deeper into the network, exfiltrate sensitive information, and spread to other systems. The danger here is not just the initial compromise, but the long term access Dora RAT provides to attackers, allowing them to monitor activities and launch further exploits.

Mapping Dora RAT’s Infrastructure

Andariel APT Dora Rat Graph

Infrastructure mapping is a critical technique for understanding the tactics, techniques, and procedures (TTPs) employed by adversaries like Andariel APT. By creating a detailed map of potential attack paths, you can better detect and block malicious activity before it escalates.

To help you visualize how Dora RAT works within the larger Andariel APT attack framework, we analyze several key components that may be involved:

1. Command and Control (C2) Infrastructure – The attacker controlled servers that communicate with infected devices.
2. Exfiltration Channels – Routes used by the malware to send stolen data back to the attackers.
3. Persistence Mechanisms – Methods used by Dora RAT to maintain access and survive reboot cycles.

Using advanced threat intelligence tools, we can map out the infrastructure used by Dora RAT and identify known indicators of compromise (IOCs) linked to its activity.

Indicators of Compromise (IOCs) to Block

To help you defend against Dora RAT, here is a table of IOCs that are critical to identify and block in your network environment:

TypeValue
IPv445.58.159.237
CVECVE-2021-44228
FileHash-MD5094f9a757c6dbd6030bc6dae3f8feab3
FileHash-MD533b2b5b7c830c34c688cf6ced287e5be
FileHash-MD5468c369893d6fc6614d24ea89e149e80
FileHash-MD54bc571925a80d4ae4aab1e8900bf753c
FileHash-MD55df3c3e1f423f1cce5bf75f067d1d05c
FileHash-SHA136fb2e182ae4348715825cfbd09eb54de7557a84
FileHash-SHA1ef3b9d308f38924ebe3970f85c8466613381cd20
FileHash-SHA2560995f1f2e4bb43ef7e3dcd57c06154fc812394ac214861c5e30084a215018dbe
FileHash-SHA25642fd586328a0dfa54af5d94905b36eb6ab59a23f49e190468a8dc55380b559fa
IPv4206.72.205.117
IPv4209.127.19.223
Hostnamekmobile.bestunif.com

Blocking these IOCs at the network perimeter, endpoint devices, and within your internal network can help stop the spread of Dora RAT and limit the damage caused by Andariel APT.

Proactive Measures to Enhance Your Defenses

While blocking IOCs is a crucial step, it’s equally important to adopt a proactive approach to cybersecurity. Here are some best practices for strengthening your defenses:

1. Regular Vulnerability Scanning – Ensure your systems are uptodate with security patches, especially for critical vulnerabilities like CVE-2021-44228 (which was exploited by Dora RAT).
2. Implement Network Segmentation – This will limit the lateral movement of attackers within your network, even if they manage to breach a single system.
3. Continuous Monitoring and Threat Intelligence – Leverage threat intelligence feeds and intrusion detection systems to stay ahead of evolving threats.
4. User Education – Train employees to recognize phishing attempts and avoid risky behavior that could lead to an initial compromise.
5. Incident Response Plan – Ensure your organization has a well documented plan for responding to incidents like Dora RAT infections to minimize the impact of an attack.

Take Action to Protect Your Organization

Dora RAT, used by the Andariel APT group, is a dangerous tool that can cause significant harm to your infrastructure. Through infrastructure mapping, you can identify and block critical attack vectors, reducing the likelihood of a successful breach. By acting on the Indicators of Compromise (IOCs) shared in this post and employing best practices for network defense, you can better protect your organization from these advanced threats.

If you’re serious about improving your security posture and defending against sophisticated APT groups, our cybersecurity solutions can help you implement a robust defense strategy. Contact us today to learn more about how we can help you safeguard your network and stay one step ahead of the everchanging threat landscape.

By providing valuable insights into Dora RAT and offering actionable steps to block malicious activity, this blog post not only raises awareness but also positions your company as a trusted partner in defending against evolving cyber threats.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]