A public GitHub repository has surfaced with a basic server emulator for SHATTEREDGLASS, a ransomware family attributed to North Korea-linked Andariel. The repository explicitly identifies the malware as SHATTEREDGLASS and ties it to external threat intelligence and malware-tracking sources, adding fresh public tooling and documentation around a ransomware strain associated with DPRK operations.
Google Cloud’s Mandiant reporting describes APT45/Andariel as a long-running North Korean threat group active since at least 2009, with operations spanning government, defense, financial, healthcare, pharmaceutical, agricultural, energy, and nuclear targets. The report says the group stands out among DPRK operators for its suspected interest in ransomware, and the newly surfaced SHATTEREDGLASS emulator reinforces the public linkage between Andariel/APT45 and ransomware activity alongside its broader espionage and disruptive mission set.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
The GitHub repository's latest visible commit, "Update README.md," is dated July 29, 2024 and describes the project as a basic server emulator for SHATTEREDGLASS attributed to Andariel.
On July 25, 2024, Google Cloud's Mandiant published a profile of APT45 describing the group as unusual among North Korean operators for its suspected interest in ransomware, while noting some ransomware-linked attribution remains unconfirmed.
The GitHub repository shows the file Unidentified081.php was added via upload on April 14, 2023 as part of a SHATTEREDGLASS server emulator project.
Mandiant said activity observed in 2023 indicated APT45 maintained interest in health-related research targets.
In 2022, CISA reported that North Korean state-sponsored actors used MAUI ransomware to target the healthcare and public health sectors.
During a suspected COVID-19 outbreak in North Korea in 2021, multiple North Korea-linked operators including APT45 focused on healthcare and pharmaceutical targets.
Mandiant identified APT45 spear-phishing a South Asian bank in 2021, showing the group's continued direct targeting of financial entities.
In 2021, Kaspersky reported on ransomware that Mandiant tracks as SHATTEREDGLASS, stating it had been used by suspected APT45-linked clusters.
Mandiant reported that APT45 targeted the crop science division of a multinational corporation in September 2020.
In 2019, APT45 directly targeted nuclear research facilities and nuclear power plants, including the Kudankulam Nuclear Power Plant in India.
Mandiant said APT45 showed a clearer operational focus on government agencies and the defense industry beginning in 2017.
In 2016, APT45 likely leveraged RIFLE to target a South Korean financial organization, reflecting the group's financially motivated operations.
Mandiant reported that malware samples indicate the North Korea-linked APT45 threat group was active by 2009.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.