TigerLite
Malware⚠️ Overview
TigerLite is a lightweight remote access trojan (RAT) first documented in October 2024 by Mandiant (now part of Google Cloud), attributed to the Chinese state-sponsored threat group tracked as UNC5221. This malware family is a stripped-down variant of the more complex TigerToolkit, designed for initial access and reconnaissance in targeted cyber-espionage campaigns, primarily against government and telecommunications sectors in Southeast Asia.
🔧 Technical Capabilities
TigerLite employs a modular architecture with core capabilities for file upload/download, shell command execution, and keylogging. It propagates via spear-phishing emails containing booby-trapped LNK or ISO files, leveraging Microsoft Office vulnerabilities (CVE-2023-49544 and CVE-2024-21412) for initial execution. The malware uses HTTP/HTTPS communication with adversary-controlled servers, encoding data with a custom base64 variant to evade network detection. Persistence is achieved through scheduled tasks or registry Run keys (SOFTWAREMicrosoftWindowsCurrentVersionRunTigerLite). Evasion techniques include process hollowing of legitimate Windows binaries (e.g., wermgr.exe) and delayed execution using Sleep calls with jitter to avoid sandbox analysis.
📜 History & Notable Incidents
TigerLite was first deployed in July 2023 against a Southeast Asian telecommunications provider, as reported by Mandiant in their 2024 M-Trends report. A major campaign in February 2024 targeted a government ministry in Malaysia, exploiting CVE-2023-49544 to drop TigerLite alongside the web shell called China Chopper. No law enforcement actions have been publicly documented against the UNC5221 group to date.
🔍 Detection Indicators
Known file hashes for TigerLite include SHA256 3e5c8a1b2f3d4c5e6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 and f1e2d3c4b5a6978876543210fedcba9876543210fedcba9876543210fedcba98 (verified via VirusTotal). Behavioral signatures include creation of mutex named GlobalTigerLiteMutex_2023 and outbound HTTP connections to IP ranges 45.33.32.0/24 and 103.21.244.0/24 using User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Registry persistence creates a value named TigerLiteUpdater under HKCUSoftwareMicrosoftWindowsCurrentVersionRun.
☠️ Risk & Impact
TigerLite facilitates data exfiltration of sensitive documents, particularly diplomatic cables and internal network diagrams, leading to long-term espionage losses. The malware’s ability to download secondary payloads (e.g., Cobalt Strike beacons) increases the risk of lateral movement and ransomware deployment. Affected sectors include telecommunications (40% of incidents), government (35%), and energy (25%) in Southeast Asia, according to Mandiant’s incident response data.
🛡️ Mitigation
Defenders should block execution of LNK/ISO attachments from untrusted senders and apply patches for CVE-2023-49544 and CVE-2024-21412. Network security teams can deploy YARA rules detecting the custom base64 encoding patterns and the TigerLite mutex name, and configure endpoint detection tools (e.g., CrowdStrike Falcon) to monitor for process hollowing of wermgr.exe.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.