Malware
ScoringMathTea
According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine. Its first appearance dates to late 2022, when its dropper was uploaded to VirusTotal. Soon after, it was seen in the wild, and since then in multiple attacks attributed to Lazarus’ Operation DreamJob campaigns, which makes it the attacker’s payload of choice for already three years. It uses compromised servers for C&C communication, with the server part usually stored under the WordPress folder containing design templates or plugins.
Indicators of Compromise 7
MITRE ATT&CK TTPs 8
T1055 T1071.001 T1085 T1090 T1134 T1203 T1218 T1480
Process Injection
Defense Evasion
Web Protocols
Command And Control
T1085
Proxy
Command And Control
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
System Binary Proxy Execution
Defense Evasion
Execution Guardrails
Defense Evasion