Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Andariel

Also known as: Silent Chollima, PLUTONIUM, Onyx Sleet, Andariel, OperationTroy, Guardian of Peace, GOP, WHOis Team, Subgroup: Andariel, Jumpy Pisces, APT38, tracked as, North Korea, North Korean

Description

Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021) Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Goals & Targeting

Targeted Sectors

Defense
Government
Financial services
Nuclear
Manufacturing
Aerospace
Healthcare
Critical infrastructure
Gaming
Transportation
Education
Energy
Maritime
Think tank

Targeted Countries / Regions

KP
KR
US
CN
RU
UA
JP
IN
VN
GB
SY
IL
AE

AI Analysis

· 1 week ago

Executive Summary

Andariel is a North Korean state-sponsored threat group linked to the Lazarus Group, primarily targeting South Korean government agencies, military organizations, and financial sectors. Known for destructive cyberattacks and cyber financial operations, Andariel has been active since at least 2009 and remains a significant espionage threat.

Goals & Targeting

Andariel's primary strategic objectives appear to be espionage and disruption of South Korean political and military infrastructure. The group targets specific sectors due to their alignment with North Korea's geopolitical interests, including gathering sensitive information and destabilizing South Korean institutions. Typical victims include government agencies, defense contractors, financial institutions, and critical infrastructure organizations in South Korea.

Enhanced Description

Andariel is a highly sophisticated North Korean state-sponsored cyber threat group that operates under the umbrella of the Lazarus Group. The group primarily focuses on South Korean government agencies, military organizations, and financial institutions, including banks, ATMs, and cryptocurrency exchanges. Andariel has been involved in notable operations such as Operation Black Mine, Operation GoldenAxe, and Campaign Rifle, which demonstrate its capability to execute large-scale, destructive cyberattacks. The group is known for its use of advanced persistent threat (APT) tactics and tools, including malware deployment and phishing attacks. Despite being a subgroup of Lazarus, Andariel has distinct operational patterns and campaigns that set it apart from the broader Lazarus activities.

Key Capabilities

  • Advanced persistent threat (APT) tactics
  • Destructive cyberattacks
  • Cyber financial operations targeting ATMs, banks, and cryptocurrency exchanges
  • Use of custom malware and remote access tools (RATs)
  • Spear-phishing campaigns with malicious file attachments
  • Exploitation of vulnerabilities for client execution
  • Steganography techniques to hide data within images

MITRE ATT&CK Tactics

Reconnaissance
Collection
Exfiltration
Impact
Validation Techniques
Defense-Evasion
Discovery

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1005
T1588.001
T1203
T1027.003

Software / Tooling

gh0st RAT
Rifdoor
Custom malware frameworks

Campaigns & Victims

Andariel has demonstrated a persistent and targeted approach, with campaigns such as Operation Black Mine and Operation GoldenAxe highlighting its ability to infiltrate critical infrastructure. The group's operational tempo appears to align with North Korea's geopolitical strategy, focusing on long-term intelligence gathering and occasional high-impact destructive attacks. Notable past operations include the 2017 WannaCry-like ransomware attack on South Korean organizations, further solidifying Andariel's reputation as a formidable threat actor.

IOC Patterns

  • Spear-phishing emails with malicious file attachments
  • Use of custom malware and remote access tools (RATs)
  • Steganography to hide data within images
  • Exploitation of vulnerabilities in client-side applications

Recommended Actions

  • Implement robust email filtering and phishing detection mechanisms.
  • Conduct regular endpoint detection and response (EDR) scans for signs of RAT activity.
  • Monitor network traffic for unusual patterns linked to Andariel TTPs.
  • Enhance incident response capabilities to address potential destructive attacks.
  • Educate employees on identifying spear-phishing attempts and suspicious emails.

Suggested Tags

APT
Nation-state
South Korea
Financial sector
Espionage

Confidence Assessment

Confidence in Andariel's details is high due to multiple credible sources linking the group to North Korea and Lazarus activities. However, some information gaps exist regarding exact timelines of their first seen activity and specific goals beyond espionage. Additionally, the overlap with Lazarus Group may complicate precise attribution in some cases.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. AhnLab Andariel Subgroup of Lazarus June 2018 — AhnLab. (2018, June 23). Targeted attacks by Andariel Threat Group, a subgroup of the Lazarus. Retrieved September 29, 2021.
  2. TrendMicro New Andariel Tactics July 2018 — Chen, Joseph. (2018, July 16). New Andariel Reconnaissance Tactics Uncovered. Retrieved September 29, 2021.
  3. CrowdStrike Silent Chollima Adversary September 2021 — CrowdStrike. (2021, September 29). Silent Chollima Adversary Profile. Retrieved September 29, 2021.
  4. FSI Andariel Campaign Rifle July 2017 — FSI. (2017, July 27). Campaign Rifle - Andariel, the Maiden of Anguish. Retrieved September 12, 2024.
  5. IssueMakersLab Andariel GoldenAxe May 2017 — IssueMakersLab. (2017, May 1). Operation GoldenAxe. Retrieved September 12, 2024.
  6. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  7. Treasury North Korean Cyber Groups September 2019 — US Treasury . (2019, September 13). Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups. Retrieved September 29, 2021.
  8. www.huntress.com — Cited by web research for: North Korea
  9. attack.mitre.org — Cited by web research for: T1592
  10. www.huntress.com — Cited by web research for: STOP
  11. www.kaspersky.com — Cited by web research for: Gentlemen
  12. www.welivesecurity.com — Cited by web research for: Crisis

Intel Summary

18

Techniques

53

Tools

7

Campaigns

3

IOCs

0

Observed Data

8

Tactics

Tags

APT
Nation-state
South Korea
Financial sector
Espionage

Details

MITRE ID
G0138
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
North Korea (KP)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--39d6890e-7f23-4474-b8ef-e7b0343c5fc8
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.