Andariel
Andariel is a DPRK-linked / North Korea-aligned threat actor. Reported aliases in the provided content include APT45, Black Chollima, DarkSeoul, Jumpy Pisces, Onyx Sleet, PLUTONIUM, Silent Chollima, Stonefly, and TDrop2 Campaign. OFAC added Andariel to the SDN List in September 2019 as a North Korea-associated entity. Based on the provided content, Andariel has conducted spearphishing campaigns using malicious Word or Excel attachments and has attempted to lure victims into enabling malicious macros within email attachments. The group has used a variety of publicly available remote access Trojans in its operations. It has also collected large numbers of files from compromised network systems for later extraction and has used tasklist to enumerate processes and search for a specific string. The content states that malware samples indicate the group was active as early as 2009, with an observed focus on government agencies and the defense industry beginning in 2017. Reported targeting later expanded to financial organizations, including a South Korean financial organization and a South Asian bank, as well as nuclear research facilities and nuclear power plants, including the Kudankulam Nuclear Power Plant in India in 2019. Additional reported targeting included agricultural, healthcare, and pharmaceutical interests, with 2023 activity indicating continued interest in health-related research. The content also states that Andariel reemerged in South Korea, where it deployed TigerRAT and attempted to spread Rook ransomware within an engineering company that appeared relevant to liquid hydrogen handling and the nuclear industry. Another report cited in the content describes Andariel malware used in an intrusion affecting a European public/legal-sector victim. The content further notes October 2024 reporting that Jumpy Pisces (Andariel) operated alongside the Play ransomware group as an initial access broker. The provided content describes APT45 as unusual among North Korean operators for suspected interest in ransomware and possible financially motivated cybercrime to support operations or broader North Korean state priorities, while also noting that some ransomware-linked attribution remains unconfirmed.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
- Banks
- Energy
- Utilities
- Pharmaceuticals, Biotechnology & Life Sciences
Where they target
Geographies tied to known operations.
- 🇰🇷 South Korea
- 🇮🇳 India
Where they're from
Attributed origin per open-source reporting.
- KP
Tradecraft
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
66 malware families attributed to this actor across reporting.
61 additional families tracked in Mallory.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The actors gain initial access through widespread exploitation of web servers through known vulnerabilities, such as CVE-2021-44228 (“Log4Shell”) in Apache’s Log4j software library... Note: CVE-2021-44228 ‘Log4Shell’ was disclosed in December 2021 and affects the Log4j library prior to version 2.17.0.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"The other victim operated a vulnerable Weblogic server. According to our telemetry, the actor compromised this server via the CVE-2017-10271 exploit."
Observables
141 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
North Korean state actor described as operating alongside Play as an initial access broker during the period associated with the November 2024 v3 compilation.
DPRK-aligned actor using AI at industrial scale to analyze CVEs and validate exploit proof-of-concepts, building a durable exploit arsenal.
Uses AI at industrial scale to recursively analyze CVEs and validate proof-of-concept exploits, building a durable exploit arsenal.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.