Overview 10 indicators
Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle. Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
| domain | 6 | G0138-domain.txt |
| ipv4 | 4 | G0138.json |
Techniques 12 ATT&CK
Open in ATT&CK Navigator → or download the layer (12 techniques, layer 4.5)
- T1005 Data from Local System
- T1027.003 Steganography
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1105 Ingress Tool Transfer
- T1189 Drive-by Compromise
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1566.001 Spearphishing Attachment
- T1588.001 Malware
- T1590.005 IP Addresses
- T1592.002 Software
Software 2
Principal sources 7 reports
Ranked by how many of this actor's indicators each report brought in.
- 4x.com/threatintel/status/1841507279150940288
- 4symantec-enterprise-blogs.security.com/threat-intelligence/stonefly-north-kore…
- 4virustotal.com/gui/ip-address/216.120.201.112/relations
- 4symantec-enterprise-blogs.security.com/blogs/threat-intelligence/stonefly-nort…
- 4otx.alienvault.com/pulse/626bba5ec3f783b80d69a882
- 2microsoft.com/en-us/security/blog/2023/10/18/multiple…
- 2otx.alienvault.com/pulse/65534130052d1800f62e7ba2
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 10 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/threatintel/status/1841507279150940288 · symantec-enterprise-blogs.security.com/threat-intelligence/stonefly-north-kore… · virustotal.com/gui/ip-address/216.120.201.112/relations
domain phpick.com domain trollbydefault.com ipv4 216.120.201.112:443 ipv4 51.81.168.157:443 -
microsoft.com/en-us/security/blog/2023/10/18/multiple… · otx.alienvault.com/pulse/65534130052d1800f62e7ba2
147.78.149.201:9090 162.19.71.175:7443 -
symantec-enterprise-blogs.security.com/blogs/threat-intelligence/stonefly-nort… · otx.alienvault.com/pulse/626bba5ec3f783b80d69a882
bluedragon.com cyancow.com semiconductboard.com tecnojournals.com
Further reading 15
- issuemakerslab.com/research3
- adversary.crowdstrike.com/en-US/adversary/silent-chollima
- attack.mitre.org/groups/G0138
- fsiceat.tistory.com/2
- home.treasury.gov/news/press-releases/sm774
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- web.archive.org/web/20230213154832/http://download.ahnl…
- trendmicro.com/en_us/research/18/g/new-andariel-reconn…
- virustotal.com/gui/ip-address/216.120.201.112/relations
- otx.alienvault.com/pulse/65534130052d1800f62e7ba2
- otx.alienvault.com/pulse/626bba5ec3f783b80d69a882
- microsoft.com/en-us/security/blog/2023/10/18/multiple…
- x.com/threatintel/status/1841507279150940288
- symantec-enterprise-blogs.security.com/threat-intelligence/stonefly-north-kore…
- symantec-enterprise-blogs.security.com/blogs/threat-intelligence/stonefly-nort…