Andariel is a North Korea-linked, DPRK-aligned threat actor associated with the Reconnaissance General Bureau (RGB) and sanctioned by OFAC in 2019 as a North Korean state-sponsored malicious cyber group. Reported aliases in the provided content include APT45, Black Chollima, DarkSeoul, Jumpy Pisces, Onyx Sleet, PLUTONIUM, Silent Chollima, Stonefly, and TDrop2 Campaign. The content describes the group as active as early as 2009, with an observed focus on government agencies and the defense industry beginning in 2017, and later targeting sectors tied to nuclear, energy, financial, healthcare, pharmaceutical, agricultural, and public/legal interests. Reported victims and targeting include South Korean and South Asian financial entities, nuclear research facilities and the Kudankulam Nuclear Power Plant in India in 2019, a European public/legal-sector victim, a Russian university, and a South Korean engineering company relevant to liquid hydrogen handling and the nuclear industry. The group has also been linked in reporting to collaboration with the Play ransomware group, where Jumpy Pisces/Andariel was identified as operating alongside Play as an initial access broker; responders reported compromised-account access, lateral movement, and persistence using DTrack malware. The content further notes Andariel’s suspected interest in ransomware, including attempted spread of Rook ransomware in South Korea, though one source states Mandiant cannot confirm ransomware use by APT45. Tactics and techniques directly mentioned in the content include spearphishing campaigns with malicious Word or Excel attachments, attempts to lure victims into enabling malicious macros, use of publicly available remote access Trojans, collection of large numbers of files from compromised network systems for later extraction, and process enumeration using tasklist to find a specific string. Additional reporting in the content states the DPRK-aligned group APT45 automated CVE analysis and proof-of-concept exploit validation through thousands of iterative prompts, indicating scaled exploit research activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
65 malware families attributed to this actor across reporting.
60 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
The actors gain initial access through widespread exploitation of web servers through known vulnerabilities, such as CVE-2021-44228 (“Log4Shell”) in Apache’s Log4j software library... Note: CVE-2021-44228 ‘Log4Shell’ was disclosed in December 2021 and affects the Log4j library prior to version 2.17.0.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"The other victim operated a vulnerable Weblogic server. According to our telemetry, the actor compromised this server via the CVE-2017-10271 exploit."
142 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
North Korean state actor described as operating alongside Play as an initial access broker during the period associated with the November 2024 v3 compilation.
DPRK-aligned actor using AI at industrial scale to analyze CVEs and validate exploit proof-of-concepts, building a durable exploit arsenal.
Uses AI at industrial scale to recursively analyze CVEs and validate proof-of-concept exploits, building a durable exploit arsenal.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.