SHATTEREDGLASS is a bespoke ransomware family associated with North Korea-linked activity, most notably clusters tied to Andariel, a Lazarus sub-group also tracked by some vendors as APT45 or Stonefly. It has been reported in operations against organizations in South Korea, Japan, and the United States, including healthcare providers, energy companies, and other critical infrastructure entities. SHATTEREDGLASS is part of a broader pattern in which Andariel combines espionage, financially motivated intrusion, and disruptive extortion tooling.
The malware is used as a ransomware payload for data encryption and extortion-oriented operations. Reporting places it alongside other Andariel-linked ransomware families such as Maui and H0lyGh0st. Its deployment has been associated with intrusions that begin through exploitation of vulnerable internet-facing systems as well as spearphishing and other social-engineering methods attributed to the operator. In broader Andariel tradecraft, post-compromise activity commonly includes credential theft, lateral movement over enterprise protocols, use of living-off-the-land administration tools, staging and exfiltration of data, and subsequent ransomware deployment.
SHATTEREDGLASS has been linked to campaigns targeting sectors of strategic and financial interest, including healthcare, energy, defense-related organizations, and other critical infrastructure. The family is notable as an example of custom ransomware used in state-linked North Korean operations, reflecting the convergence of intelligence collection and revenue generation in Andariel activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
a basic server emulator for an unnamed North Korean ransomware (now known as SHATTEREDGLASS) attributed to Andariel.
...a Lazarus sub-cluster referred to as Andariel (aka Stonefly) was observed striking entities in South Korea, Japan, and the U.S. with bespoke ransomware families like SHATTEREDGLASS and Maui.
1 distinct technique documented for this family, organized by ATT&CK tactic.
In 2022, the U.S. Cybersecurity and Infrastructure Security Agency reported on North Korean state-sponsored actors' use of MAUI ransomware to target the healthcare and public health sectors. In 2021, Kaspersky reported on the identification of ransomware tracked by Mandiant as SHATTEREDGLASS, which has been used by suspected APT45 clusters.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware family previously deployed by Andariel, mentioned as background context for North Korean ransomware activity.
Ransomware strain attributed in the content to Andariel deployments against healthcare, energy, and other critical infrastructure targets.
A bespoke ransomware family used by the Lazarus sub-cluster Andariel in attacks against entities in South Korea, Japan, and the U.S.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.