AndarLoader is a .NET downloader associated with the North Korea-aligned Andariel threat group, also tracked under the broader Lazarus ecosystem. It has been observed in espionage-focused intrusions targeting organizations in South Korea, including ICT, electronics, shipbuilding, manufacturing, and other strategically relevant sectors, and is also listed among malware families associated with Andariel operations more broadly.
The malware is obfuscated and communicates with command-and-control infrastructure over SSL-like encrypted channels. Its primary role is to retrieve and execute additional .NET payloads rather than provide a full interactive implant by itself. Reported command functionality includes downloading and launching external assemblies or methods, terminating execution, and self-removal. In observed intrusions, AndarLoader was used as a staging component to deploy follow-on tooling, including credential-access utilities such as Mimikatz, making it part of a broader post-compromise toolchain.
Operational reporting links AndarLoader with other Andariel malware families including DurianBeacon, and evidence has indicated that DurianBeacon can create or install AndarLoader on compromised hosts. Tradecraft surrounding these infections suggests delivery through spearphishing and script-based execution chains involving native Windows components, although Andariel is also known to obtain access through exploitation of public-facing applications and other intrusion vectors. The malware runs on Windows systems and fits Andariel’s long-standing pattern of combining custom loaders, RATs, and dual-use tools to support espionage, credential access, persistence, lateral movement, and data theft against defense-related and industrial targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ AndarLoader
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A .NET loader/downloader obfuscated with Dotfuscator and using SSL C2. It receives commands to download and execute .NET assemblies or methods, terminate, and self-delete; it was also observed installing Mimikatz and showing spear-phishing-like tradecraft.
Custom loader used to stage/execute additional implants and tooling on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.