A sweeping coalition of U.S. and international cybersecurity agencies has issued a joint advisory warning that North Korea's Andariel threat group — also tracked as Onyx Sleet, Silent Chollima, and Stonefly — is waging a sustained global cyber espionage campaign aimed at advancing Pyongyang's military and nuclear ambitions.
A State-Sponsored Espionage Machine
The advisory, co-authored by the FBI, CISA, NSA, U.S. Cyber National Mission Force, and intelligence agencies from South Korea and the United Kingdom, attributes the activity to the Reconnaissance General Bureau (RGB) 3rd Bureau, based in Pyongyang and Sinuiju. The group primarily targets defense, aerospace, nuclear, and engineering entities worldwide to steal sensitive classified technical information and intellectual property.
Targeted intelligence spans an alarming range: from uranium processing and enrichment data to fighter aircraft and missile defense system blueprints, submarine and torpedo designs, satellite technology, and advanced manufacturing processes. The authoring agencies assess that satisfying collection requirements for North Korea's nuclear and defense programs is among the group's chief responsibilities.
Ransomware Funds the Espionage
In a dual-threat model, Andariel funds its espionage operations through ransomware attacks against U.S. healthcare entities. The advisory notes that in some instances, ransomware deployment and espionage operations occurred on the same day — and even against the same victim organization.
Exploitation Tactics and Custom Tooling
Initial access is achieved primarily through exploitation of known vulnerabilities in public-facing web servers, most notably CVE-2021-44228 (Log4Shell). The advisory catalogs over 30 CVEs the group actively researches and exploits, including flaws in Apache ActiveMQ, TeamCity, Citrix NetScaler, MOVEit, and Fortinet SSL VPN.
Post-compromise, the actors deploy an extensive arsenal of custom remote access trojans:
- TigerRAT, MagicRAT, NukeSped, and YamaBot for persistent remote access
- Mimikatz and ProcDump for credential theft
- Commercial packers VMProtect and Themida for defense evasion
- Tunneling tools like 3Proxy, PLINK, and Stunnel for C2 communications
The group also leverages living-off-the-land techniques, using native tools such as cmd.exe, PowerShell, and netstat commands for enumeration. Analysts noted frequent typos in operator commands, including the recurring error "Microsoft Cooperation" — indicating commands are improvised rather than scripted.
Global Implications
The advisory urges critical infrastructure organizations to patch vulnerabilities promptly, monitor for web shell activity, and strengthen authentication controls. The authoring agencies assess the group remains an ongoing threat to defense, aerospace, nuclear, energy, and engineering sectors across the United States, South Korea, Japan, India, and the United Kingdom.