SHATTEREDGLASS is a bespoke ransomware family associated with North Korea-linked intrusion activity, particularly clusters suspected to overlap with Andariel, also known as Stonefly, and activity tracked by some vendors as APT45. It has been observed in operations against organizations in South Korea, Japan, and the United States, including healthcare providers, energy companies, and other critical infrastructure entities. Reporting places it alongside other custom ransomware families used in the same ecosystem, including Maui and H0lyGh0st.
SHATTEREDGLASS is used as an encryption-and-extortion payload in broader post-compromise operations rather than as a commodity mass-distributed threat. Its deployment has been linked to actors that combine espionage, financially motivated intrusion, and disruptive activity. These operators are known for gaining access through exploitation of internet-facing systems and spearphishing, then conducting credential theft, internal reconnaissance, lateral movement, staging, and data theft before deploying ransomware. The broader actor tradecraft associated with SHATTEREDGLASS use includes abuse of legitimate administrative tools, credential-dumping utilities, remote access protocols, and exfiltration channels to support both intelligence collection and revenue generation.
The malware is notable because it reflects the use of custom ransomware by a state-linked North Korean operator, an approach that differs from purely criminal ransomware-as-a-service models. Public reporting has described SHATTEREDGLASS as having been used by suspected APT45-linked clusters, although attribution of some ransomware-linked activity to APT45 remains assessed rather than definitively confirmed. High-confidence reporting nevertheless places SHATTEREDGLASS within the Andariel/Lazarus-associated ransomware toolkit used against strategically significant sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Andariel itself has a track record of deploying custom ransomware families like SHATTEREDGLASS, Maui, and H0lyGh0st in the past.
...a Lazarus sub-cluster referred to as Andariel (aka Stonefly) was observed striking entities in South Korea, Japan, and the U.S. with bespoke ransomware families like SHATTEREDGLASS and Maui.
1 distinct technique documented for this family, organized by ATT&CK tactic.
In 2022, the U.S. Cybersecurity and Infrastructure Security Agency reported on North Korean state-sponsored actors' use of MAUI ransomware to target the healthcare and public health sectors. In 2021, Kaspersky reported on the identification of ransomware tracked by Mandiant as SHATTEREDGLASS, which has been used by suspected APT45 clusters.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware family previously deployed by Andariel, mentioned as background context for North Korean ransomware activity.
Ransomware strain attributed in the content to Andariel deployments against healthcare, energy, and other critical infrastructure targets.
A bespoke ransomware family used by the Lazarus sub-cluster Andariel in attacks against entities in South Korea, Japan, and the U.S.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.