THREATOPS Actor Dossier
LIVE ← Dashboard

Andariel

G01381 reports
aliases · Andariel · Silent Chollima · PLUTONIUM · Onyx Sleet
Export dossier:
1
Reports
12
Techniques
10
Tactics
2
Countries
23%
Hunt coverage
4
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1132.001 (Standard Encoding), T1556.003 (Pluggable Authentication Modules), T1059.007 (JavaScript).
  • Primary targeting: KP, KR.
  • Newly emerged: 1 report(s) in last 30d vs 0 prior (+100%).
  • Recent movement: 35 new technique(s), 31 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 23% of 35 observed techniques (27 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

Newly emergedLast 30d: 1 vs 0 prior (+100%)· first reported 2026-09-04 · last 2026-09-04
0
7d
1
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
T1132.001T1556.003T1059.007T1543T1539T1036.005T1497.001T1588.006T1119T1082T1071T1106
Targeting gained
KPKR
New infrastructure
4bb923eb040aa13ca8fd409c31ee4729c60ddff35db1b6d52faf60b4f32d6fd0c7c938e4d05d29a109739441ed4599bac2f8159028f772f71e4b25c8fea1bc36632c71e5a839803469ef60ac47595d36feeea9d0bf6ae7396d28271baa51ae50df5169ce8f30b57928934ae67478d0e690c91d046e35a63872e70936f0dbe459142a1d867617c35f8d0cce5da8bfab4de81a1acb04aacdf757346946b0f5e30f83f7d565b0465546027052b597af46eae3a199e77007a78d50a993cb174c685eba96eb442c9507e36cf1b5e92a9c0756f597a5ddefb38eba32961c52ed72f4cd8d467b5c5d95ae6aeca4aaeea14d7956

Overview

Analyst triage
Intelligence summary

Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021)

Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019)

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected