Juggernaut is an open-source or dual-use tool identified in a joint FBI-led Cybersecurity Advisory as used and/or customized by the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau threat group Andariel, also tracked as Onyx Sleet and formerly PLUTONIUM. In the cited reporting, Juggernaut is listed among the actors’ supporting tooling rather than described as a bespoke malware family. The advisory associates its use with a broader Andariel intrusion lifecycle that includes exploitation of public-facing web servers using known vulnerabilities such as Log4Shell (CVE-2021-44228), deployment of web shells, persistence via Scheduled Tasks, credential theft with tools such as Mimikatz, lateral movement over SMB and RDP, and data exfiltration via cloud services or tools such as PuTTY and WinSCP. The campaign primarily targets defense, aerospace, nuclear, and engineering organizations for sensitive military and technical information, with additional targeting of medical and energy sectors. The provided content does not give Juggernaut-specific infection vectors, standalone capabilities, or indicators of compromise beyond its inclusion in the list of open-source and dual-use tools used or customized by Andariel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Juggernaut [T1040]
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Juggernaut [T1040]
The authoring agencies have identified the following open source and dual-use tools as used and/or customized by the actors: ▪ Juggernaut [T1040]
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.