Andariel
G01381 reportsAnalyst assessment — key judgments
- Signature techniques: T1132.001 (Standard Encoding), T1556.003 (Pluggable Authentication Modules), T1059.007 (JavaScript).
- Primary targeting: KP, KR.
- Newly emerged: 1 report(s) in last 30d vs 0 prior (+100%).
- Recent movement: 35 new technique(s), 31 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 23% of 35 observed techniques (27 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Overview
Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021)
Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019)
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
ATT&CK technique matrix
- T1132.001 · Standard Encodingconf 601
- T1556.003 · Pluggable Authentication Modulesconf 601
- T1059.007 · JavaScriptconf 601
- T1543 · Create or Modify System Processconf 601
- T1539 · Steal Web Session Cookieconf 601
- T1036.005 · Match Legitimate Resource Name or Locationconf 601
- T1497.001 · System Checksconf 601
- T1588.006 · Vulnerabilitiesconf 601
- T1119 · Automated Collectionconf 601
- T1082 · System Information Discoveryconf 601
- T1071 · Application Layer Protocolconf 601
- T1106 · Native APIconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|