Andariel — APT Profile
Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle. Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Silent Chollima, PLUTONIUM, Onyx Sleet, DarkSeoul, Stonefly, Clasiopa, Guardian of Peace, WHOis Team
IntelFusions coverage (10)
- North Korea's hacking machine is bigger than Lazarus 2026-09-07 · Nation-State
- Hacked Korean websites pushed spy backdoors and Gunra ransomware 2026-07-30 · Nation-State
- CISA warns of critical flaws across industrial control systems 2026-06-30 · Vulnerabilities
- North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration 2026-02-16 · Ransomware
- Andariel Acted as Play Ransomware Precursor in Five-Month Network Siege, Unit 42 Reveals 2026-02-16 · Nation-State
- Microsoft Reveals Andariel's New Dora RAT and Decade-Long Malware Arsenal Targeting Aerospace and Defence 2026-02-16 · Nation-State
- U.S. and Allied Agencies Warn of North Korean Andariel Espionage Campaign Targeting Defense and Nuclear Sectors 2026-02-16 · Nation-State
- Mandiant Designates Andariel as APT45: North Korea's Nuclear Blueprint-Stealing Unit Fully Exposed 2026-02-16 · Nation-State
- Microsoft Exposes Onyx Sleet's Expanding Malware Arsenal Targeting Aerospace and Defense Organizations 2026-02-16 · Nation-State
- Lazarus Group (APT38): North Korea's Most Prolific Cyber Threat Actor Targets Banks, Crypto, and Critical Infrastructure 2026-02-16 · Nation-State
Tools & malware
- 3Proxy tool
- AndarLoader malware
- AsyncRAT malware
- Atharvan malware
- Black RAT malware
- BottomLoader malware
- DeimosC2 tool
- Dtrack malware
- DurianBeacon malware
- gh0st RAT Remote Access Trojan
- Goat RAT malware
- Impacket tool
- Jupiter malware
- KaosRAT malware
- Lilith RAT malware
- MagicRAT malware
- Nestdoor malware
- NineRAT malware
- NukeSped malware
- PLINK tool
- Preft malware
- ProcDump tool
- PuTTY tool
- RDP Wrapper tool
- Rifdoor Backdoor
- Stunnel tool
- TigerRAT malware
- Trifaux malware
- ValidAlpha malware
- VSingle malware
- WinRAR tool
- YamaBot malware
Vendor research
- AA24-207A: North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs CISA
- Mandiant Google Threat Intelligence
- Unit 42 Unit 42
- Microsoft Threat Intelligence Microsoft
- How Microsoft names threat actors Microsoft
- Targeted attacks by Andariel Threat Group, a subgroup of the Lazarus AhnLab
- Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups Treasury
- New Andariel Reconnaissance Tactics Uncovered TrendMicro
- Silent Chollima Adversary Profile Crowdstrike
- Campaign Rifle - Andariel, the Maiden of Anguish FSI
- Operation GoldenAxe IssueMakersLab Andariel GoldenAxe
Countries linked to this actor
- North Korea origin
- South Korea targets