Threat actor
Andariel
Last fetched
Andariel is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 97 techniques and also known as 3 other names.
Also known as
Silent Chollima, PLUTONIUM, Onyx Sleet
Description
[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. [Andariel](https://attack.mitre.org/groups/G0138)'s notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021) [Andariel](https://attack.mitre.org/groups/G0138) is considered a sub-set of [Lazarus Group](https://attack.mitre.org/groups/G0032), and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1008 · Fallback Channels
- T1071.001 · Web Protocols
- T1090.001 · Internal Proxy
- T1090.002 · External Proxy
- T1102.002 · Bidirectional Communication
- T1104 · Multi-Stage Channels
- T1105 · Ingress Tool Transfer
- T1132.001 · Standard Encoding
- T1571 · Non-Standard Port
- T1573.001 · Symmetric Cryptography
Discovery
- T1010 · Application Window Discovery
- T1012 · Query Registry
- T1016 · System Network Configuration Discovery
- T1033 · System Owner/User Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1124 · System Time Discovery
- T1680 · Local Storage Discovery
Stealth
- T1027.003 · Steganography
- T1027.007 · Dynamic API Resolution
- T1027.009 · Embedded Payloads
- T1027.013 · Encrypted/Encoded File
- T1036.003 · Rename Legitimate Utilities
- T1036.004 · Masquerade Task or Service
- T1036.005 · Match Legitimate Resource Name or Location
- T1055.001 · Dynamic-link Library Injection
- T1070 · Indicator Removal
- T1070.003 · Clear Command History
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1078 · Valid Accounts
- T1134.002 · Create Process with Token
- T1140 · Deobfuscate/Decode Files or Information
- T1202 · Indirect Command Execution
- T1218 · System Binary Proxy Execution
- T1218.005 · Mshta
- T1218.011 · Rundll32
- T1542.003 · Bootkit
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.013 · KernelCallbackTable
- T1620 · Reflective Code Loading
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Andariel today — this states the absence of a published link, not that Andariel has no infrastructure.
References
- http://www.issuemakerslab.com/research3/
- https://adversary.crowdstrike.com/en-US/adversary/silent-chollima/
- https://attack.mitre.org/groups/G0138
- https://fsiceat.tistory.com/2
- https://home.treasury.gov/news/press-releases/sm774
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://web.archive.org/web/20230213154832/http://download.ahnlab.com/global/brochure/%5BAnalysis%5DAndariel_Group.pdf
- https://www.trendmicro.com/en_us/research/18/g/new-andariel-reconnaissance-tactics-hint-at-next-targets.html
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Andariel into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.