🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
ANDARIEL

/actor/andariel/  ·  0 intel reports

Year Established
2015
Attribution
North Korea (RGB Bureau 121)
Motivation
Financial, Espionage, Ransomware
Modus Operandi (MO)
Healthcare ransomware, defence contractor espionage, cryptocurrency theft
Primary Aliases
Silent Chollima, Stonefly, DarkSeoul, APT45

Andariel is a sub-group of North Korea's Lazarus Group ecosystem, operating under the Reconnaissance General Bureau's (RGB) Bureau 121 with a primary focus on financial crime to generate revenue for the North Korean state and targeted espionage against South Korean military and defence organisations. Andariel is distinguished from other Lazarus sub-groups by its specific focus on ransomware deployment against the healthcare sector and South Korean defence industrial base espionage.

The group's ransomware operations have targeted US hospital networks, healthcare providers, and medical research institutions, generating cryptocurrency ransom payments that fund North Korean state operations. US government agencies have specifically called out Andariel's pattern of targeting hospitals , including during the COVID-19 pandemic , as a particularly egregious element of North Korea's state-sanctioned cybercrime operations, given the direct threat to patient safety from healthcare system disruptions.

On the espionage front, Andariel has conducted sustained campaigns against South Korean defence contractors, government agencies, and military-adjacent organisations, seeking technical specifications for weapons systems, military doctrine documents, and strategic assessments that inform North Korean military planning and weapons development programmes. The group employs both spear-phishing and watering hole attacks to gain initial access to target networks.

In 2024, the US Department of Justice indicted a North Korean national associated with Andariel for ransomware attacks against multiple US hospitals and US defence contractors, providing unprecedented public detail about Andariel's dual financial crime and espionage mandate. The indictment alleged that ransom proceeds from hospital attacks were directly used to fund Andariel's defence contractor espionage operations , illustrating the integrated nature of North Korean cyber operations.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Andariel requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles