ATT&CKGroupsAndariel

Andariel

G0138

Threat group.View on attack.mitre.org

About this group

Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.

Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau.

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1005
Data from Local System

Andariel has collected large numbers of files from compromised network systems for later extraction.

T1027.003
Steganography

Andariel has hidden malicious executables within PNG files.

T1049
System Network Connections Discovery

Andariel has used the netstat -naop tcp command to display TCP connections on a victim's machine.

T1057
Process Discovery

Andariel has used tasklist to enumerate processes and find a specific string.

T1105
Ingress Tool Transfer

Andariel has downloaded additional tools and malware onto compromised hosts.

T1189
Drive-by Compromise

Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.

T1203
Exploitation for Client Execution

Andariel has exploited numerous ActiveX vulnerabilities, including zero-days.

T1204.002
Malicious File

Andariel has attempted to lure victims into enabling malicious macros within email attachments.

T1566.001
Spearphishing Attachment

Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments.

T1588.001
Malware

Andariel has used a variety of publicly-available remote access Trojans (RATs) for its operations.

T1590.005
IP Addresses

Andariel has limited its watering hole attacks to specific IP address ranges.

T1592.002
Software

Andariel has inserted a malicious script within compromised websites to collect potential victim information such as browser type, system language, Flash Player version, and other data.

Software2

Campaigns0

None recorded.

References6

  1. AhnLab Andariel Subgroup of Lazarus June 2018 Open source
    AhnLab. (2018, June 23). Targeted attacks by Andariel Threat Group, a subgroup of the Lazarus. Retrieved September 29, 2021.
  2. CrowdStrike Silent Chollima Adversary September 2021 Open source
    CrowdStrike. (2021, September 29). Silent Chollima Adversary Profile. Retrieved September 29, 2021.
  3. FSI Andariel Campaign Rifle July 2017 Open source
    FSI. (2017, July 27). Campaign Rifle - Andariel, the Maiden of Anguish. Retrieved September 12, 2024.
  4. IssueMakersLab Andariel GoldenAxe May 2017 Open source
    IssueMakersLab. (2017, May 1). Operation GoldenAxe. Retrieved September 12, 2024.
  5. Treasury North Korean Cyber Groups September 2019 Open source
    US Treasury . (2019, September 13). Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups. Retrieved September 29, 2021.
  6. TrendMicro New Andariel Tactics July 2018 Open source
    Chen, Joseph. (2018, July 16). New Andariel Reconnaissance Tactics Uncovered. Retrieved September 29, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.