Andariel is a North Korean state-sponsored threat actor widely assessed as a subgroup or cluster within the Lazarus ecosystem and linked to the Reconnaissance General Bureau, including reporting that ties it to the RGB’s 3rd bureau and broader DPRK cyber apparatus. It is also tracked under aliases including APT45, Black Chollima, Onyx Sleet, Plutonium, Silent Chollima, Stonefly, Jumpy Pisces, and DarkSeoul in some reporting contexts. Andariel has historically focused heavily on South Korean targets, including government, public-sector, legal, financial, media, defense-adjacent, enterprise software, and private-sector organizations, while later reporting also places it against victims in Europe and other regions. Its operations span cyber espionage, disruptive activity, financially motivated intrusions, and ransomware deployment. Public reporting has associated the actor with long-running campaigns against South Korean entities, ERP software targeting, and destructive or disruptive activity connected to the DarkSeoul lineage. More recent investigations also attribute to Andariel intrusions against a European public/legal-sector victim and campaigns involving energy-sector targeting under the broader Lazarus umbrella. The group commonly uses spearphishing attachments and malicious documents that require user execution, including lures designed to induce victims to enable macros. It has also been linked to watering-hole and drive-by compromise activity, exploitation of vulnerable internet-facing services and enterprise software, and supply-chain-style access paths through trusted software or sector-specific platforms. After initial access, Andariel conducts host and network reconnaissance, including process discovery with native utilities such as tasklist, system and account enumeration, and collection of documents and other files for later exfiltration. Andariel is known for extensive use of remote access trojans and modular malware. Malware and tooling associated with the actor include TigerRAT, TigerDownloader, NukeSped, Dtrack, Maui ransomware, and previously undocumented implants such as StarshellRAT, JelusRAT, and GopherRAT. Reported capabilities across these tools include shell access, file management, screen capture, keylogging, SOCKS tunneling, port forwarding, system information gathering, payload download and execution, and self-deletion. The actor has also used publicly available RATs and additional post-compromise tooling to expand access and blend operations with commodity tradecraft. Observed post-exploitation behavior includes downloading additional malware and tools, persistence via startup mechanisms and scheduled execution, privilege escalation with tools such as PrintSpoofer and PetitPotato, credential theft, lateral movement, and exfiltration of large volumes of files. Reporting also documents defense evasion through anti-analysis packing, junk-code insertion, sandbox checks, timestomping, process injection, DLL side-loading, and bring-your-own-vulnerable-driver techniques used to disable antivirus and EDR products. In some campaigns, operators performed hands-on-keyboard activity, created unauthorized accounts, tunneled traffic through proxying tools, and adapted malware families over time while retaining recognizable Lazarus tradecraft. Andariel’s dominant role is best characterized as DPRK-directed espionage in support of state objectives, though the actor has also been tied to financially motivated operations and ransomware use. Its activity illustrates the overlap within the Lazarus constellation between intelligence collection, disruptive operations, and revenue-generating cyber campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
61 malware families attributed to this actor across reporting.
56 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Andariel 그룹은 취약한 버전의 VMware Horizon 제품을 사용하는 국내 기업을 대상으로 Log4Shell 취약점 공격을 수행해 TigerRat을 설치한 사례도 존재한다.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"The other victim operated a vulnerable Weblogic server. According to our telemetry, the actor compromised this server via the CVE-2017-10271 exploit."
260 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive threat actor cluster linked in the report to the Sony Pictures intrusion and earlier destructive attacks dating back to at least 2009, and described as still active primarily targeting South Korean organizations across multiple sectors.
Mentioned for tradecraft similarity only, specifically abuse of South Korean ERP solutions to distribute malware. Not presented as the primary actor in this report.
Mentioned for comparison because Larva-26005 used an ERP software patching technique similar to methods previously attributed to Andariel.
North Korean unit referenced as prior evidence of Pyongyang-linked actors engaging in ransomware attacks, specifically against U.S. hospitals and healthcare companies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.