Trending
ee-track">
Link copied!

Table of Contents

Andariel

Threat Actor Profile: Andariel

Overview

Andariel is a North Korean state-sponsored threat actor associated with the Reconnaissance General Bureau (RGB) 3rd Bureau and the broader Lazarus ecosystem.  

The group is also known as APT45, Andariel, GOP, Guardian of Peace, Onyx Sleet, PLUTONIUM, Plutonium, Silent Chollima, Stonefly, WHOis Team, and under numerous operation names, including Operation “BLACKMINE,” Operation “BLACKSHEEP”/Phase 3, Operation “Blacksmith,” Operation “DESERTWOLF”/Phase 3, Operation “GHOSTRAT,” Operation “GoldenAxe,” Operation “INITROY”/Phase 1, Operation “INITROY”/Phase 2, Operation “Mayday,” Operation “VANXATM,” Operation “XEDA,” and OperationTroy. 

image 5

Andariel has historically targeted South Korean organizations through spearphishing, watering-hole attacks, supply-chain activity, and exploitation of publicly exposed vulnerabilities.  

Its operations combine cyber espionage with financially motivated activity, including ransomware attacks against healthcare organizations. U.S. and allied agencies assess that the group has evolved from destructive operations against U.S. and South Korean targets into specialized espionage and ransomware activity supporting North Korea’s military, nuclear, and strategic objectives. 

Origin, Targets, and Strategic Objectives 

Andariel is assessed as part of the RGB 3rd Bureau, with activity associated with Pyongyang and Sinuiju. Its primary espionage targets include defense, aerospace, nuclear, and engineering organizations, while medical and energy entities have also been targeted. 

The group seeks information such as contract specifications, bills of materials, project details, design drawings, engineering documents, intellectual property, and technical information with potential military and civilian applications.  

image 7
An overview of Andariel 

The actor’s activity extends beyond South Korea and the United States to organizations in Japan, India, Taiwan, China, and other countries worldwide. U.S. agencies have linked Andariel activity to compromises involving two U.S. Air Force bases, NASA’s Office of Inspector General, defense contractors, South Korean and Taiwanese organizations, and a Chinese energy company.  

The group also uses ransomware as a revenue-generating mechanism. According to U.S. authorities, ransom proceeds obtained from attacks on U.S. healthcare entities were laundered through China-based facilitators and used to acquire infrastructure for subsequent intrusions against defense, technology, government, and military-related targets.  

In some cases, ransomware and espionage activity were conducted against the same organization or on the same day.  

Operational Capabilities 

Andariel maintains a broad operational toolkit spanning custom malware, publicly available RATs, credential theft utilities, web shells, and legitimate system functionality. 

  • Initial Access – The group exploits internet-facing vulnerabilities, including Log4Shell and flaws in enterprise applications, while also using spearphishing attachments, watering holes, and malicious files. 
  • Execution and Persistence – Actors deploy web shells, Scheduled Tasks, custom malware, RATs, and open-source tools to execute commands and maintain access. 
  • Privilege Escalation – Tools such as Mimikatz and CreateHiddenAccount are used to obtain elevated privileges. CreateHiddenAccount supports RID Hijacking by manipulating accounts and Security Account Manager (SAM) registry information. 
  • Reconnaissance – Andariel performs system and network discovery and researches newly disclosed vulnerabilities and exposed infrastructure. 
  • Collection and Exfiltration – The group collects large quantities of files and sensitive technical information before transferring additional tools or stolen information through compromised environments. 
  • Defense Evasion – Malicious executables may be concealed using techniques such as steganography, while malware has also employed packing and file-hash modification to complicate detection. 

Malware and Tooling 

The supplied profile identifies four primary malware/tool entries: CreateHiddenAccount, Gh0st RAT, Dtrack, and Rifdoor. Gh0st RAT provides reconnaissance, backdoor, keylogging, and information-stealing capabilities; Dtrack supports backdoor, information-stealing, and exfiltration activity; and Rifdoor provides remote-access functionality. 

image 8
Malware families and tools used by Andariel (Source: Cyble Vision)

Rifdoor, first identified in November 2015, shares code similarities with HotCroissant and was active into early 2016. It was associated with attacks against SEOUL ADEX exhibitors and security companies and can alter file hashes after infection to hinder detection. 

CISA and partner agencies have also documented a broader Andariel toolset developed over approximately 15 years, including Atharvan, ELF Backdoor, Jupiter, MagicRAT, “No Pineapple,” TigerRAT, Valefor/VSingle, ValidAlpha, YamaBot, NukeSped, Goat RAT, Black RAT, AndarLoader, DurianBeacon, Trifaux, KaosRAT, Preft, and Andariel Scheduled Task Malware.  

Reconnaissance and Exploitation 

Andariel has used publicly available scanning capabilities and open-source information to identify vulnerable systems and potential targets. The group researches CVEs published through the NIST National Vulnerability Database and has been associated with exploitation of a broad range of enterprise technologies, including: 

  • CVE-2023-46604 – Apache ActiveMQ 
  • CVE-2023-42793 – TeamCity 
  • CVE-2023-3519 – Citrix NetScaler 
  • CVE-2023-35078 – Ivanti Endpoint Manager Mobile (EPMM) 
  • CVE-2023-34362 – MOVEit 
  • CVE-2023-33246 – RocketMQ 
  • CVE-2023-32784 – KeePass 
  • CVE-2023-32315 – Openfire 
  • CVE-2023-3079 – Google Chromium V8 
  • CVE-2023-28771 – Zyxel firmware 
  • CVE-2023-33010 – Zyxel firmware 
  • CVE-2023-2868 – Barracuda Email Security Gateway 
  • CVE-2023-27997 – FortiGate SSL VPN 
  • CVE-2023-25690 – Apache HTTP Server 
  • CVE-2023-21932 – Oracle Hospitality OPERA 5 
  • CVE-2023-0669 – GoAnywhere MFT 
  • CVE-2022-47966 – ManageEngine 
  • CVE-2022-41352 – Zimbra Collaboration Suite 
  • CVE-2022-27925 – Zimbra Collaboration Suite 
  • CVE-2022-30190 – Microsoft Windows Support Diagnostic Tool 
  • CVE-2022-25064 – TP-LINK 
  • CVE-2022-24990 – TerraMaster NAS 
  • CVE-2022-24785 – Moment.js 
  • CVE-2022-24665 – PHP Everywhere 
  • CVE-2022-24664 – PHP Everywhere 
  • CVE-2022-24663 – PHP Everywhere 
  • CVE-2022-22965 – Spring4Shell 
  • CVE-2022-22947 – Spring Cloud Gateway 
  • CVE-2022-22005 – Microsoft SharePoint Server 
  • CVE-2022-21882 – Win32k 
  • CVE-2021-45837 – TerraMaster NAS 
  • CVE-2021-44228 – Apache Log4j / Log4Shell 
  • CVE-2021-44142 – Samba vfs_fruit module 
  • CVE-2021-43226 – Windows 
  • CVE-2021-43207 – Windows 
  • CVE-2021-36955 – Windows 
  • CVE-2021-41773 – Apache HTTP Server 2.4.49 
  • CVE-2021-40684 – Talend ESB Runtime 
  • CVE-2021-3018 – IPeakCMS 3.5 
  • CVE-2021-20038 – SMA100 / SonicWall 
  • CVE-2021-20028 – SonicWall Secure Remote Access (SRA) 
  • CVE-2019-15637 – Tableau 
  • CVE-2019-7609 – Kibana 
  • CVE-2019-0708 – Microsoft Remote Desktop Services (RDP) 
  • CVE-2017-4946 – VMware V4H / V4PA 

Ransomware and Law-Enforcement Activity 

On 24 July 2024, a Kansas grand jury indicted North Korean national Rim Jong Hyok over an alleged conspiracy involving ransomware attacks against U.S. hospitals and healthcare providers, money laundering, and subsequent intrusions against defense, technology, and government organizations. The U.S. Department of Justice stated that Rim and co-conspirators worked for the RGB and were known in the private sector as Andariel, Onyx Sleet, and APT45.  

The indictment alleged that ransomware proceeds were laundered through China-based facilitators, including conversion of cryptocurrency into Chinese yuan, and subsequently used to obtain infrastructure for further attacks.  

Reported victims of the subsequent espionage activity included two U.S. Air Force bases, NASA-OIG, and organizations in Taiwan, South Korea, and China. Stolen information included U.S. government employee data, military aircraft information, intellectual property, and technical information related to maritime and uranium-processing projects.  

Tactics, Techniques, and Procedures 

Andariel’s documented ATT&CK activity includes Drive-by Compromise through watering-hole attacks, including campaigns restricted to specific IP ranges; Spearphishing Attachment using malicious Word or Excel files; Exploitation for Client Execution involving ActiveX vulnerabilities, including zero-days; and User Execution: Malicious File through attempts to persuade victims to enable malicious macros. 

For defense evasion, the group has used Steganography to conceal malicious executables inside PNG files. Discovery activity includes System Network Connections Discovery using netstat -naop tcp and Process Discovery using tasklist. Collection includes Data from the local system, while Ingress Tool Transfer is used to introduce additional malware and tooling. 

Within resource development, Andariel has used publicly available RATs under Malware. Its reconnaissance activity includes IP Addresses and Software, including malicious scripts inserted into compromised websites to collect information such as browser type, system language, and Flash Player version. 

Conclusion 

Andariel remains a persistent and evolving threat, combining state-sponsored cyber espionage with ransomware and sophisticated intrusion techniques targeting sensitive organizations worldwide. Its focus on defense, aerospace, nuclear, engineering, healthcare, and government entities makes continuous visibility into its activity essential. 

Track this threat actor in real time with Cyble Vision. Monitor emerging Andariel activity, infrastructure, vulnerabilities, and threat intelligence to identify potential risks early and strengthen your organization’s defenses. Request a Cyble Vision demo to see how real-time threat intelligence can help your security team stay ahead of evolving threats. 

Mitigations and Recommendations 

  • Patch internet-facing systems quickly, prioritizing Log4Shell and other known vulnerabilities. 
  • Protect web servers with asset inventories, timely updates, reverse proxies, authentication controls, and properly configured WAFs. 
  • Monitor endpoints for suspicious command-line activity, unauthorized Scheduled Tasks, malware execution, dual-use tools, and unusual outbound connections. 
  • Strengthen remote access by enforcing MFA and restricting or disabling unnecessary administrator panels and exposed services. 
  • Segment critical networks to limit lateral movement following a compromise. 
  • Protect sensitive information through encryption, unused-port restrictions, and prompt password changes after suspected credential compromise. 
  • Strengthen infrastructure security by improving authentication for leased servers and maintaining effective incident-response and threat-hunting procedures. 
  • Prioritize these controls for defense, aerospace, nuclear, engineering, healthcare, energy, government, and other organizations handling sensitive intellectual property or critical infrastructure. 

MITRE ATT&CK Techniques Associated with Andariel 

image 9
MITRE ATT&CK Techniques (Source: Cyble Vision) 
  • Initial Access — Drive-by Compromise (T1189): Used watering-hole attacks, often involving zero-day exploits, to gain initial access to victims within specific IP address ranges. 
  • Initial Access — Spearphishing Attachment (T1566.001): Conducted spearphishing campaigns using malicious Word or Excel attachments. 
  • Execution — Exploitation for Client Execution (T1203): Exploited numerous ActiveX vulnerabilities, including zero-day vulnerabilities. 
  • Execution — Malicious File (T1204.002): Attempted to persuade victims to enable malicious macros contained within email attachments. 
  • Stealth — Steganography (T1027.003): Concealed malicious executables within PNG image files. 
  • Discovery — System Network Connections Discovery (T1049): Used netstat -naop tcp to display TCP connections on compromised systems. 
  • Discovery — Process Discovery (T1057): Used tasklist to enumerate running processes and search for specific strings. 
  • Collection — Data from Local System (T1005): Collected large numbers of files from compromised network systems for subsequent extraction. 
  • Command and Control — Ingress Tool Transfer (T1105): Downloaded additional tools and malware onto compromised hosts. 
  • Resource Development — Malware (T1588.001): Used a variety of publicly available remote access Trojans in its operations. 
  • Reconnaissance — IP Addresses (T1590.005): Restricted watering-hole attacks to specific IP address ranges. 
  • Reconnaissance — Software (T1592.002): Inserted malicious scripts into compromised websites to collect potential victim information, including browser type, system language, Flash Player version, and other system characteristics. 

References:  

Media Disclaimer: This content is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. Cyble assumes no liability for the accuracy or consequences of using this information. 

Discover how we help proactively defend against evolving threats with Gen 3 intelligence. Request a Demo today!

Share Post:

Stay Informed

The Cyber Briefing Security Teams Actually Read!

Join security teams across 50+ countries getting Cyble's weekly research, advisories, and analyst insights.

No spam, ever. Unsubscribe anytime.

Related Topics

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams