Unmasking Dora RAT: Defend Against Andariel APT with Effective Infrastructure Mapping
In the ever evolving landscape of cybersecurity, threat actors are continuously adapting and refining their tactics to bypass traditional defenses.

Uncovering the Hidden Threat: Investigating Dora RAT Used by Andariel APT and Strengthening Your Infrastructure with Threat Mapping
In the ever evolving landscape of cybersecurity, threat actors are continuously adapting and refining their tactics to bypass traditional defenses. One particularly concerning threat comes from the Andariel APT, an advanced persistent threat group associated with North Korea. A critical component of Andariel’s toolkit is the Dora RAT (Remote Access Trojan), a stealthy and powerful malware designed to infiltrate networks, steal sensitive data, and maintain longterm access to compromised systems.
As cyberattacks grow in complexity and frequency, it’s essential to have the right tools and strategies in place to protect your infrastructure. One highly effective way to defend against threats like Dora RAT is through Infrastructure Mapping. By understanding your network’s layout and using threat intelligence to track potential attack vectors, you can detect and neutralize threats before they cause significant damage.
In this post, we’ll explore the infrastructure map of Dora RAT used by Andariel APT, provide insights on how these attacks unfold, and introduce steps for fortifying your defenses using threat detection tools. Additionally, we’ll provide a comprehensive list of Indicators of Compromise (IOCs) associated with Dora RAT that you can use to block malicious activity and improve your network security posture.
Understanding the Dora RAT and Andariel APT
The Andariel APT group is known for its sophisticated attacks targeting governments, defense contractors, and critical infrastructure worldwide. Their Dora RAT is a highly effective backdoor Trojan that allows attackers to gain remote access to infected systems, exfiltrate data, and move laterally within networks. Once deployed, Dora RAT operates in stealth, avoiding detection by conventional security tools.
Andariel’s campaign often involves multistage attacks, including:
Initial phishing or social engineering attacks to gain access.
Exploiting vulnerabilities in systems (e.g., CVE-2021-44228) to install malware.
Maintaining persistence through backdoors, like Dora RAT, for long term access.
Once an organization is compromised, the attackers can use Dora RAT to infiltrate deeper into the network, exfiltrate sensitive information, and spread to other systems. The danger here is not just the initial compromise, but the long term access Dora RAT provides to attackers, allowing them to monitor activities and launch further exploits.
Mapping Dora RAT’s Infrastructure

Infrastructure mapping is a critical technique for understanding the tactics, techniques, and procedures (TTPs) employed by adversaries like Andariel APT. By creating a detailed map of potential attack paths, you can better detect and block malicious activity before it escalates.
To help you visualize how Dora RAT works within the larger Andariel APT attack framework, we analyze several key components that may be involved:
1. Command and Control (C2) Infrastructure – The attacker controlled servers that communicate with infected devices.
2. Exfiltration Channels – Routes used by the malware to send stolen data back to the attackers.
3. Persistence Mechanisms – Methods used by Dora RAT to maintain access and survive reboot cycles.
Using advanced threat intelligence tools, we can map out the infrastructure used by Dora RAT and identify known indicators of compromise (IOCs) linked to its activity.
Indicators of Compromise (IOCs) to Block
To help you defend against Dora RAT, here is a table of IOCs that are critical to identify and block in your network environment:
| Type | Value |
|---|---|
| IPv4 | 45.58.159.237 |
| CVE | CVE-2021-44228 |
| FileHash-MD5 | 094f9a757c6dbd6030bc6dae3f8feab3 |
| FileHash-MD5 | 33b2b5b7c830c34c688cf6ced287e5be |
| FileHash-MD5 | 468c369893d6fc6614d24ea89e149e80 |
| FileHash-MD5 | 4bc571925a80d4ae4aab1e8900bf753c |
| FileHash-MD5 | 5df3c3e1f423f1cce5bf75f067d1d05c |
| FileHash-SHA1 | 36fb2e182ae4348715825cfbd09eb54de7557a84 |
| FileHash-SHA1 | ef3b9d308f38924ebe3970f85c8466613381cd20 |
| FileHash-SHA256 | 0995f1f2e4bb43ef7e3dcd57c06154fc812394ac214861c5e30084a215018dbe |
| FileHash-SHA256 | 42fd586328a0dfa54af5d94905b36eb6ab59a23f49e190468a8dc55380b559fa |
| IPv4 | 206.72.205.117 |
| IPv4 | 209.127.19.223 |
| Hostname | kmobile.bestunif.com |
Blocking these IOCs at the network perimeter, endpoint devices, and within your internal network can help stop the spread of Dora RAT and limit the damage caused by Andariel APT.
Proactive Measures to Enhance Your Defenses
While blocking IOCs is a crucial step, it’s equally important to adopt a proactive approach to cybersecurity. Here are some best practices for strengthening your defenses:
1. Regular Vulnerability Scanning – Ensure your systems are uptodate with security patches, especially for critical vulnerabilities like CVE-2021-44228 (which was exploited by Dora RAT).
2. Implement Network Segmentation – This will limit the lateral movement of attackers within your network, even if they manage to breach a single system.
3. Continuous Monitoring and Threat Intelligence – Leverage threat intelligence feeds and intrusion detection systems to stay ahead of evolving threats.
4. User Education – Train employees to recognize phishing attempts and avoid risky behavior that could lead to an initial compromise.
5. Incident Response Plan – Ensure your organization has a well documented plan for responding to incidents like Dora RAT infections to minimize the impact of an attack.
Take Action to Protect Your Organization
Dora RAT, used by the Andariel APT group, is a dangerous tool that can cause significant harm to your infrastructure. Through infrastructure mapping, you can identify and block critical attack vectors, reducing the likelihood of a successful breach. By acting on the Indicators of Compromise (IOCs) shared in this post and employing best practices for network defense, you can better protect your organization from these advanced threats.
If you’re serious about improving your security posture and defending against sophisticated APT groups, our cybersecurity solutions can help you implement a robust defense strategy. Contact us today to learn more about how we can help you safeguard your network and stay one step ahead of the everchanging threat landscape.
By providing valuable insights into Dora RAT and offering actionable steps to block malicious activity, this blog post not only raises awareness but also positions your company as a trusted partner in defending against evolving cyber threats.



