Malware
TigerLite
TigerLite is a TCP downloader. It creates mutexes like "qtrgads32" or "Microsoft32".
TigerLite is a Windows malware family operated by Silent Chollima.
Background
TigerLite is a TCP-based downloader.
It generates mutexes such as "qtrgads32" or "Microsoft32".
For decrypting its strings it relies on RC4 with the key "MicrosoftCorporationValidation@#$%^&*()!US", while a custom algorithm handles encryption and decryption of its network traffic.
The downloader handles between 5 and 8 commands, identified by the values 1111, 1234, 2099/3333, 4444, 8877, 8888, 9876, and 9999. Most of these carry out some form of execution, running either code supplied by the server or native Windows commands, and return the resulting output to the server.
TigerLite serves as an intermediate stage within a multi-stage attack, typically followed by Tiger RAT. It was seen in operations against South Korean targets during the first half of 2021.
Source: Malpedia (Fraunhofer FKIE).