Microsoft Threat Intelligence has published a comprehensive analysis of Onyx Sleet — the North Korean state-sponsored group also known as Andariel, APT45, and Silent Chollima — revealing an expanding toolkit of custom malware used to infiltrate aerospace and defense organizations worldwide.
A Decade of Persistent Espionage
First observed by Microsoft in 2014, Onyx Sleet has conducted cyber espionage campaigns targeting military, defense, and technology industries, predominantly in India, South Korea, and the United States. The disclosure coincides with a U.S. Department of Justice indictment of an individual linked to the group, underscoring the escalating law enforcement response to North Korean cyber operations.
New Malware Families in the Wild
Microsoft's research highlights several custom malware families recently deployed by the group:
- TigerRAT — Active since 2020, this RAT enables keylogging, screen recording, and confidential data theft. Delivery has leveraged CVE-2021-44228 (Log4j 2) exploitation.
- SmallTiger — A C++ backdoor first identified in February 2024 targeting South Korean defense and manufacturing organizations. It features layered obfuscation and is packed with Themida or VMProtect.
- LightHand — A lightweight custom backdoor providing remote command execution, directory listing, and file management capabilities.
- ValidAlpha (BlackRAT) — A Go-based backdoor targeting energy, defense, and engineering sectors globally since at least 2023, capable of screenshots, file operations, and arbitrary command execution.
N-Day Exploitation and Signed Malware
Onyx Sleet has shifted from spear-phishing to primarily exploiting publicly disclosed vulnerabilities for initial access. Recently exploited CVEs include CVE-2023-46604 (Apache ActiveMQ), CVE-2023-42793 (TeamCity), CVE-2023-22515 (Confluence), and CVE-2023-27350 (PaperCut). In a notable campaign from October 2023 to June 2024, the group deployed a Sliver implant signed with an invalid certificate impersonating Tableau software, compromising multiple aerospace and defense targets.
South Korean Defense Data Theft
In December 2023, South Korean authorities attributed attacks that exfiltrated over 1.2 TB of data from targeted defense contractors to Andariel. Microsoft confirmed that the custom malware families used — TigerRAT, SmallTiger, LightHand, and ValidAlpha — belong to the Onyx Sleet toolset.
Defense Evasion at Scale
The group employs heavy custom encryption and obfuscation, executing as much code in memory as possible to evade detection. Commercial packers like VMProtect and Themida are routinely applied to late-stage payloads. Off-the-shelf tools including Sliver, SOCKS proxy utilities, Ngrok, and masscan round out a versatile operational toolkit.
Microsoft recommends organizations keep software updated, enable cloud-delivered protection, and run endpoint detection in block mode to defend against these persistent campaigns.