Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: GRASS NEPTUNE, Onyx Sleet, North Korean, Andariel, Silent Chollima, Razor Tiger, Rattlesnake, T-APT-04, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, North Korea, Nickel Hyatt, Stonefly

Description

APT45 emerged in the late 2000s from the broader North Korean Lazarus Group ecosystem and has evolved into a sophisticated threat actor that blends espionage with state‑directed destructive operations. The group develops custom malware modules—ranging from backdoors to exfiltration scripts—while also selling and reusing off‑the‑shelf ransomware-as-a-service (RaaS) families such as MAUI, SHATTEREDGLASS, and BlackCat. Their toolset employs AI‑enhanced code generation for rapid iteration of malicious payloads, and they routinely exploit new zero‑day vulnerabilities (e.g., Log4Shell, CVE‑2026‑35273) to gain initial access. APT45’s operational profile is distinctly dual: one layer executes long‑term espionage against defense contractors and government networks, harvesting sensitive data about military technology, nuclear programs and critical infrastructure. A second layer delivers financially motivated ransomware, double‑extortion campaigns, and targeted sabotage of industrial control systems—executed through TRITON‑style attacks on safety components—and includes cryptocurrency laundering operations. Their tactics combine traditional spearphishing with watering hole compromises, use living‑off‑the‑land techniques for lateral movement, and rely heavily on scheduled tasks and persistence mechanisms. The group’s campaigns have been documented across the United States, Europe, the Middle East and Asia. Recent public disclosures record ransomware incidents against U.S. hospitals, logistics firms, and sophisticated data exfiltration from defense industrial bases, underscoring APT45’s capacity to adapt its methods to emerging security postures while remaining tightly aligned with North Korea’s strategic objectives.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Manufacturing
Non profit
Media
Critical infrastructure
Energy
Pharmaceutical
Aviation
Hospitality
Aerospace
Nuclear
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

CN
US
KP
RU
JP
IR
GB
UA
VN
IL
AU
KR
SA
PK
TW
AE
IN
SG
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 10 hours ago

Executive Summary

APT45, a North Korean state‑backed actor also known as Andariel and Silent Chollima, conducts a hybrid cyber campaign that blends intelligence gathering with destructive sabotage and ransomware attacks. Their operations target high‑value defense, industrial control systems and critical infrastructure worldwide, leveraging custom backdoors, zero‑day exploits, and RaaS platforms such as MAUI and BlackCat to maintain persistence and maximize financial gains.

Goals & Targeting

APT45 seeks to secure regime intelligence by infiltrating military, nuclear, and defense industrial networks worldwide, harvesting technical information that could advance North Korean weapons capabilities. Simultaneously, the actor pursues economic pressure against rival nations through ransomware, data theft, and sabotage of critical infrastructure, thereby applying a multi‑pronged approach that blends political, strategic and financial objectives.

Enhanced Description

Key Capabilities

  • Backdoor deployment (custom & commodity RATs)
  • Destructive wiper attacks
  • Phishing-based credential theft / spearphishing with malicious Office attachments
  • Cryptocurrency financial operations / laundering
  • Supply chain compromise
  • Watering hole attacks targeting specific IP ranges
  • Zero‑day exploits for initial access
  • Credential harvesting and lateral movement tools
  • Ransomware-as-a-Service operations (MAUI, SHATTEREDGLASS, BlackCat)
  • Destructive sabotage of industrial control systems
  • Exfiltration module development & staging
  • Scheduled task persistence & living‑off‑the‑land techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Exfiltration
Command and Control
Impact

ATT&CK Techniques

T1005
T1048
T1057
T1068
T1071.001
T1086
T1105
T1189
T1190
T1195
T1203
T1204
T1204.002
T1590
T1590.005
T1592
T1592.002
T1587.001
T1588
T1566
T1566.001
T1027

Software / Tooling

Akira
AppleJeus
Bumblebee
Cobalt
Conti
Dark
Darkside Ransomware
Dtrack (Preft)
Ebury SSH backdoor
Enigma?
Gold Southfield RaaS
Guard
Hafnium
Hard?
Hermit
Hunters International
Indrik Spider
Keyhole
Kinsing
Kimsuky
Latrodectus
LockBit 3.0
Machete
MAUI
MAUI Ransomware
Masscan
Medusa
Moonstone Sleet
Ngrok
Octopus
Panda?
Plankton?
Play
Polaris?
Posh?
QakBot
Revenge RAT
ShatterED Glass
ShadowPad
Sliver
SMALLTIGER
Sonar??
Stealth?
Sudoku?
Sabbath Ransomware
SHATTEREDGLASS
SilverEye?
Snowflake?
Star?
Stellar?
Steampunk?
STORM?
Stonefly?
Storm?
Submarine?
Sunflower?
Support?
TRITON
TigerRAT
Trojan
Turbine?
Valefor
Virgo?
Void
Wargame?
Winnti
Workhorse?
WWT?
Zero-day exploits

Campaigns & Victims

APT45 has a global operational tempo, conducting multi‑phase campaigns that begin with credential harvesting or spearphishing before escalating to persistent backdoor installation. Victim types range from defense contractors in the United States and Europe to critical infrastructure operators in Asia and the Middle East. The actor’s notable past operations include large‑scale ransomware attacks on U.S. hospitals, a sabotage attempt against South Korean military networks (Operation Black Mine), and supply‑chain compromise incidents that leveraged third‑party software updates. Patterns show a preference for exploiting fresh zero‑days to bypass traditional defenses and a propensity to pair stealthy espionage threads with high‑impact destructive payloads when financial or strategic objectives align.

IOC Patterns

  • Domain
  • Email Address
  • Malicious File Hash
  • Watering Hole URL
  • Spearphishing Attachment

Recommended Actions

  • Implement strict monitoring for known malware families such as Agent Tesla and ShadowPad, ensuring real‑time detection of backdoor activity.
  • Deploy EDR solutions capable of identifying destructive wiper activities and ransomware signatures from MAUI, BlackCat, and SHATTEREDGLASS.
  • Educate users on phishing indicators; enforce multi‑factor authentication to mitigate credential theft.
  • Apply supply chain hardening controls to detect compromise of third‑party software dependencies and review signed binaries.
  • Implement domain filtering and block known malicious URLs to defend against watering hole attacks.
  • Enhance email security, filter attachments with malicious content, and use attachment sandboxing tools.
  • Conduct regular phishing awareness training exercises for all staff.
  • Prioritize vulnerability patch management, especially addressing zero‑day vulnerabilities leveraged by APT45.
  • Monitor network traffic for indicators of data exfiltration over alternative protocols (e.g., T1048 usage) and anomalous lateral movement patterns.
  • Deploy IDS/IPS to block identified RaaS infrastructure traffic (MAUI, BlackCat, SHATTEREDGLASS).
  • Enable logging and alerts for scheduled tasks and living‑off‑the‑land tool execution to detect persistence attempts.

Suggested Tags

APT45
North Korean state-sponsored
Lazarus Group
Backdoor
Destructive Attack
Cryptocurrency Laundering
Phishing
Supply Chain Compromise
Andariel
Silent Chollima
Watering Hole
Spearphishing
Zero-Day Exploit
Financial Targeting
Ransomware-as-a-Service
Industrial Control Systems Attacks

Confidence Assessment

The confidence in the core capabilities, tactics and attribution of APT45 is high, supported by multiple independent industry reports and threat intelligence feeds. However, gaps remain regarding precise timelines, specific victims for newer campaigns, and the full extent of their destructive sabotage operations; these limitations should guide ongoing monitoring and data collection.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 Email Address 1

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. www.huntress.com — Cited by web research for: North Korea
  3. rewterz.com — Cited by web research for: Nickel Hyatt
  4. attack.mitre.org — Cited by web research for: T1189
  5. cloud.google.com — Cited by web research for: Naikon
  6. cloud.google.com — Cited by web research for: b.aqdrmf
  7. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a — Cited by AI analysis.
  8. https://cyberwarrior76.substack.com/p/cyber-threat-intelligence-briefing-6ce — Cited by AI analysis.
  9. https://thehackernews.com/2024/07/north-korean-hackers-shift-from-cyber.html — Cited by AI analysis.
  10. https://www.picussecurity.com/resource/blog/lazarus-group-apt38-explained-timeline-ttps-and-major-attacks — Cited by AI analysis.
  11. https://www.huntress.com/threat-library/silent-chollima — Cited by AI analysis.
  12. https://www.brandefense.io/blog/silent-chollima-apt45-2025/ — Cited by AI analysis.
  13. https://www.microsoft.com/en-us/security/blog/2024/07/25/onyx-sleet-uses-array-of-malware-to-gather-intelligence-for-north-korea/ — Cited by AI analysis.
  14. https://www.cisa.gov/sites/default/files/publications/AAP_230718_GS20.pdf — Cited by AI analysis.
  15. https://www.picussecurity.com/resource/blog/andariel-north-korean-apt-group-targets-military-and-nuclear-programs — Cited by AI analysis.
  16. https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla — Cited by AI analysis.
  17. https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowpad — Cited by AI analysis.

Intel Summary

23

Techniques

117

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

Ransomware
APT
Healthcare Targeting
Critical Infrastructure
Government Targeting
North Korea
State-sponsored
Financial Sector
APT45
Silent Chollima
Andariel
Onyx Sleet
Stonefly
North Korean
Cyber Espionage
Defense Industrial Base
Vulnerability Exploitation
Log4Shell
CVE‑2026‑35273
AI‑Driven Threats
Financially Motivated
Data‑Staging
Zero‑Day Exploit
Watering Hole
Steganography
Credential Dumping
Custom RAT
North Korean state-sponsored
Lazarus Group
Backdoor
Destructive Attack
Cryptocurrency Laundering
Phishing
Supply Chain Compromise
Silent Chollima
Watering Hole
Spearphishing
Zero-Day Exploit
Financial Targeting
Ransomware-as-a-Service
Industrial Control Systems Attacks

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.