Also known as: GRASS NEPTUNE, Onyx Sleet, North Korean, Andariel, Silent Chollima, Razor Tiger, Rattlesnake, T-APT-04, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, North Korea, Nickel Hyatt, Stonefly
APT45 emerged in the late 2000s from the broader North Korean Lazarus Group ecosystem and has evolved into a sophisticated threat actor that blends espionage with state‑directed destructive operations. The group develops custom malware modules—ranging from backdoors to exfiltration scripts—while also selling and reusing off‑the‑shelf ransomware-as-a-service (RaaS) families such as MAUI, SHATTEREDGLASS, and BlackCat. Their toolset employs AI‑enhanced code generation for rapid iteration of malicious payloads, and they routinely exploit new zero‑day vulnerabilities (e.g., Log4Shell, CVE‑2026‑35273) to gain initial access. APT45’s operational profile is distinctly dual: one layer executes long‑term espionage against defense contractors and government networks, harvesting sensitive data about military technology, nuclear programs and critical infrastructure. A second layer delivers financially motivated ransomware, double‑extortion campaigns, and targeted sabotage of industrial control systems—executed through TRITON‑style attacks on safety components—and includes cryptocurrency laundering operations. Their tactics combine traditional spearphishing with watering hole compromises, use living‑off‑the‑land techniques for lateral movement, and rely heavily on scheduled tasks and persistence mechanisms. The group’s campaigns have been documented across the United States, Europe, the Middle East and Asia. Recent public disclosures record ransomware incidents against U.S. hospitals, logistics firms, and sophisticated data exfiltration from defense industrial bases, underscoring APT45’s capacity to adapt its methods to emerging security postures while remaining tightly aligned with North Korea’s strategic objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT45, a North Korean state‑backed actor also known as Andariel and Silent Chollima, conducts a hybrid cyber campaign that blends intelligence gathering with destructive sabotage and ransomware attacks. Their operations target high‑value defense, industrial control systems and critical infrastructure worldwide, leveraging custom backdoors, zero‑day exploits, and RaaS platforms such as MAUI and BlackCat to maintain persistence and maximize financial gains.
Goals & Targeting
APT45 seeks to secure regime intelligence by infiltrating military, nuclear, and defense industrial networks worldwide, harvesting technical information that could advance North Korean weapons capabilities. Simultaneously, the actor pursues economic pressure against rival nations through ransomware, data theft, and sabotage of critical infrastructure, thereby applying a multi‑pronged approach that blends political, strategic and financial objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT45 has a global operational tempo, conducting multi‑phase campaigns that begin with credential harvesting or spearphishing before escalating to persistent backdoor installation. Victim types range from defense contractors in the United States and Europe to critical infrastructure operators in Asia and the Middle East. The actor’s notable past operations include large‑scale ransomware attacks on U.S. hospitals, a sabotage attempt against South Korean military networks (Operation Black Mine), and supply‑chain compromise incidents that leveraged third‑party software updates. Patterns show a preference for exploiting fresh zero‑days to bypass traditional defenses and a propensity to pair stealthy espionage threads with high‑impact destructive payloads when financial or strategic objectives align.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core capabilities, tactics and attribution of APT45 is high, supported by multiple independent industry reports and threat intelligence feeds. However, gaps remain regarding precise timelines, specific victims for newer campaigns, and the full extent of their destructive sabotage operations; these limitations should guide ongoing monitoring and data collection.
No campaigns linked yet.
No observed data linked yet.
23
Techniques
117
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics