August 26, 2026
Updated: August 26, 2026
How an RGB-linked actor combines strategic intelligence collection with a source-qualified ransomware mission
Mohammed Khalil

Andariel is frequently summarized as a North Korean hacking group, a Lazarus subgroup, an espionage actor, or a ransomware operator. Each description captures part of the public record, but none is precise enough by itself. The name sits inside overlapping government and vendor taxonomies, and those sources do not always assign the same activity with the same confidence.
For defenders, the useful question is not which alias wins. It is which behaviors have been credibly reported, what mission they may support, and which evidence would confirm that a similar path exists in the organization's own environment.
Andariel is a North Korean state-sponsored threat group associated with the Reconnaissance General Bureau and active since at least 2009. MITRE tracks it as G0138 and considers it a subset of Lazarus Group, while Mandiant calls overlapping activity APT45 and Microsoft uses Onyx Sleet. Its core mission is strategic espionage against defense, aerospace, nuclear, engineering, government, and technology targets. U.S. authorities also connect an Andariel unit to Maui ransomware attacks on healthcare organizations, alleging that ransom proceeds funded later espionage. These labels overlap, but they are not automatically interchangeable.
| Question | Evidence-led answer |
|---|---|
| What is Andariel? | A North Korean state-sponsored activity set associated with the Reconnaissance General Bureau |
| How long has it operated? | Since at least 2009, according to MITRE and Mandiant |
| Is it part of Lazarus Group? | MITRE and U.S. Treasury describe it as a subset or subgroup; other sources track it as a distinguishable cluster |
| Are APT45 and Onyx Sleet exact aliases? | They substantially overlap with Andariel reporting, but source scopes are not guaranteed to match 1:1 |
| What is its primary mission? | Strategic intelligence collection, particularly against defense, aerospace, nuclear, engineering, and technology targets |
| Does it use ransomware? | U.S. authorities connect an Andariel unit to Maui; Mandiant assesses ransomware involvement more cautiously for its APT45 cluster |
| What access paths recur? | Exploitation of exposed software, targeted phishing, loaders/backdoors, credentials, remote tooling, and long-term collection |
| Is it still relevant in 2026? | Yes; GTIG published fresh APT45 defense-sector observations in February 2026, and MITRE updated G0138 in July 2026 |
DeepStrike's broader Lazarus Group profile explains the umbrella label and its wider history. This article owns the narrower Andariel entity, its dual mission, and the evidence defenders need to distinguish an actor hypothesis from an incident fact.
MITRE ATT&CK describes Andariel as a North Korean state-sponsored threat group active since at least 2009. Its historical operations have included destructive attacks against South Korean government, military, and commercial organizations, along with financial activity affecting ATMs, banks, and cryptocurrency exchanges. MITRE assigns the group ID G0138 and describes it as a subset of Lazarus Group attributed to the Reconnaissance General Bureau. The profile was last modified July 31, 2026. See the current MITRE ATT&CK Andariel profile.
The U.S. Treasury took a policy and sanctions view in September 2019. It identified Andariel, Lazarus Group, and Bluenoroff as agencies, instrumentalities, or controlled entities of the North Korean government based on their relationship to the RGB. Treasury described Andariel as a Lazarus subgroup that conducted both revenue-generating cybercrime and intelligence collection, particularly against South Korean government and military targets. That is an official designation, not a complete technical organization chart.
Mandiant uses APT45 for a long-running cluster it assesses with high confidence to support North Korean state interests and with moderate confidence to be attributable specifically to the RGB. Its research traces activity to at least 2009 and emphasizes a relatively distinct malware lineage, shifting target priorities, and an unusual combination of espionage with suspected ransomware development. The Mandiant APT45 assessment is therefore close to, but not necessarily identical with, every use of “Andariel.”
The practical conclusion is narrow: Andariel is not merely a media nickname and not simply a malware family. It is an attribution label for a long-running North Korean activity set whose exact edges depend on the reporting source.
Threat-actor names are analytical models. Governments, MITRE, and security vendors cluster evidence using different visibility, thresholds, time windows, and purposes. One source may group activity by sponsor or unit; another may split it by infrastructure, malware lineage, or victimology.
The July 2024 joint advisory made this limitation explicit. It said the cybersecurity industry uses overlapping names including Andariel, Onyx Sleet, and DarkSeoul for activity associated with the RGB 3rd Bureau, but warned that vendor groupings may not correlate 1:1 with the U.S. government's understanding. The NSA announcement for the joint advisory preserves that boundary.
| Label | Primary source using it | What it represents | Safe interpretation |
|---|---|---|---|
| Andariel | MITRE, U.S. government, multiple vendors | Named North Korean activity set; MITRE G0138 | Use for the entity when the source does, while retaining its scope and date |
| APT45 | Mandiant / Google | Vendor-defined DPRK operator cluster | Strongly overlaps Andariel reporting; do not import every claim from another taxonomy automatically |
| Onyx Sleet | Microsoft | Microsoft-defined North Korean actor cluster | Overlaps Andariel/APT45; Microsoft also reports affiliations with other DPRK clusters |
| PLUTONIUM | Microsoft legacy naming | Earlier Microsoft label associated with Onyx Sleet | Historical vendor label, not a separate proof point |
| Silent Chollima | CrowdStrike and public reporting | Vendor activity label associated with Andariel | Preserve source-specific scope |
| Stonefly / Clasiopa | Symantec/Broadcom and public reporting | Vendor cluster associated with related activity | Overlaps, but the matching boundary can vary by incident |
| Lazarus Group | Governments, MITRE, vendors, media | Broad actor or umbrella label | Do not replace every narrower DPRK cluster with “Lazarus” |
Microsoft's own 2024 profile says other security companies track Onyx Sleet as APT45, Silent Chollima, Andariel, DarkSeoul, Stonefly, and TDrop2. It also reports operational overlap with Storm-0530, a separate cluster associated with H0lyGh0st ransomware. An observed relationship is not the same as identity, and a tool used by both does not collapse the groups into one.
The safest writing rule is simple: retain the original source's name, date, and confidence. For incident response, record three conclusions separately what happened, which technical cluster best fits, and which sponsor or unit a government or vendor attributes it to.
| Period | Public record | Evidence boundary |
|---|---|---|
| 2009 onward | MITRE and Mandiant trace Andariel/APT45 activity to at least 2009 | An activity range, not a verified founding date |
| 2015–2019 | Industry reporting increasingly separated Andariel from the broader Lazarus label; Treasury designated it in September 2019 | Treasury's subgroup framing is a policy attribution and may differ from vendor clustering |
| 2019–2021 | Mandiant reports targeting related to nuclear, energy, agriculture, healthcare, defense, government, and finance | Targeting changed with assessed DPRK priorities; not every sector appears in every campaign |
| 2021–2022 | Public reporting connected suspected Andariel-related clusters with ransomware; U.S. agencies warned about North Korean use of Maui against healthcare | The 2022 advisory used a broad DPRK label; later 2024 legal and government reporting narrowed the Andariel connection |
| 2023–June 2024 | Microsoft observed Onyx Sleet exploiting known vulnerabilities and using custom and public tools against defense, aerospace, manufacturing, education, construction, engineering, and energy targets | Microsoft taxonomy; individual campaigns require their own attribution evidence |
| July 25, 2024 | A multinational advisory described the RGB 3rd Bureau's global espionage and ransomware funding; DOJ announced charges against Rim Jong Hyok | The advisory is an assessment; the indictment contains allegations and is not a conviction |
| August–October 2024 | Symantec reported three U.S. private-sector intrusions it attributed to Stonefly and assessed as likely financially motivated; it saw no successful ransomware deployment | Useful continuity evidence, not proof of the intended final payload |
| February 10, 2026 | GTIG reported directly observing APT45 campaigns targeting defense-sector individuals and identified a suspected SMALLTIGER operation | A current vendor observation; it does not make every job-themed approach APT45 |
| July 31, 2026 | MITRE modified the Andariel G0138 profile | Confirms a current knowledge-base review, not a new incident by itself |
The 2019 Treasury action remains an important anchor because it publicly tied the Andariel label to the RGB and described both revenue and intelligence objectives. Its sanctions announcement should be read as dated official attribution, not as a permanent map of every North Korean intrusion set.
As of the August 26, 2026 research cutoff, the FBI still lists Rim Jong Hyok as wanted for alleged computer-hacking and promotion-money-laundering conspiracies. A wanted notice and indictment establish the government's allegation and current law-enforcement posture; they do not establish guilt.
The joint advisory says the RGB 3rd Bureau primarily targets defense, aerospace, nuclear, and engineering organizations to obtain sensitive technical information and intellectual property that could advance North Korea's military and nuclear programs. It describes an ongoing threat to sectors worldwide, including organizations in the United States, South Korea, Japan, and India.
Mandiant's history adds government, energy, nuclear research, financial services, agriculture, healthcare, and pharmaceutical research. These targets should not be flattened into a generic “critical infrastructure” label. The likely value differs: military designs, engineering processes, energy information, scientific research, operational access, or funds.
In February 2026, Google Threat Intelligence Group said it had directly observed APT45, APT43, and UNC2970 campaigns targeting people at defense organizations. It also identified a suspected APT45 operation using SMALLTIGER against reported South Korean defense, semiconductor, and automotive manufacturing targets. The GTIG defense-industrial-base report makes personnel and hiring workflows part of the current defensive picture.
The U.S. government's 2024 assessment goes beyond saying that a North Korean actor used ransomware. It links the RGB 3rd Bureau activity discussed in the advisory with ransomware operations against U.S. healthcare entities that funded espionage. DOJ alleged that Rim Jong Hyok and co-conspirators used Maui ransomware to extort healthcare providers, laundered the proceeds, and used funds to lease infrastructure for later intrusions against defense, technology, and government targets.
Mandiant is more cautious for its APT45 cluster. It assesses with moderate confidence that APT45 engaged in ransomware development, while stating that it could not confirm APT45 attribution for every ransomware-related cluster in public reporting. Both positions can coexist because the sources use different scopes and evidence.
The distinction matters. “Andariel uses ransomware” is supportable when tied to the U.S. government's narrower unit-level assessment and allegations. “Every Maui or H0lyGh0st incident is APT45” is not. “APT45 is primarily a ransomware gang” is also inaccurate because strategic collection is central to its public history.
DeepStrike's North Korean cryptocurrency operations analysis owns the broader DPRK financial-theft topic. Andariel's public revenue evidence should not be merged with every Lazarus- or BlueNoroff-linked cryptocurrency case.
MITRE notes destructive activity in Andariel's historical record. Access to a strategically valuable network can also create options: quiet collection now, broader access later, or disruptive impact if objectives change. Defenders should therefore protect confidentiality, integrity, and availability rather than assuming that espionage produces no operational risk.
| Sector or asset | Why it may be valuable | Defensive priority |
|---|---|---|
| Defense and aerospace | Military platforms, R&D, engineering data, suppliers, personnel, and project access | Protect identities, endpoints, repositories, collaboration systems, suppliers, and data egress |
| Nuclear and energy | Technical research, plant or engineering information, and strategic intelligence | Segment sensitive environments, control engineering-data access, and centralize identity and network logs |
| Government and military | Policy, operational, employee, and technical information | Use phishing-resistant MFA, privileged-access controls, and high-value-user monitoring |
| Technology and engineering | Intellectual property, software, designs, infrastructure, and trusted relationships | Patch exposed systems, protect source and build systems, and monitor unusual bulk access |
| Healthcare and pharmaceuticals | Ransomware impact, operational urgency, health research, and sensitive data | Isolate critical services, protect backups, rehearse downtime, and report incidents rapidly |
| Manufacturing, construction, and education | Technical knowledge, supply-chain position, research, and opportunistic access | Inventory exposed services, segment business units, and monitor remote tooling and data movement |
| Financial services and selected online businesses | Funds, payment data, or revenue opportunities | Separate approvals, monitor anomalous transactions, and investigate identity-plus-endpoint sequences |
The target list is an exposure model, not a prediction. A company in one of these sectors is not necessarily being targeted, and an intrusion in the sector is not automatically Andariel. DeepStrike's overview of state-sponsored hacking and APT threats provides the wider comparison context.
No single chain represents every campaign. Public reporting supports a set of recurring defensive possibilities:
Recent Microsoft reporting shows why attack-surface management matters: Onyx Sleet has exploited multiple already disclosed vulnerabilities in internet-facing products. The lesson is not to hunt only those five CVEs forever; it is to maintain ownership, exposure, patch, and telemetry coverage for every public-facing service.
MITRE's G0138 profile is a historical, source-aggregated knowledge base. It is not a checklist guaranteed to appear in a current intrusion, and technique overlap cannot establish attribution.
| Technique | ID | Publicly reported Andariel use | High-value telemetry |
|---|---|---|---|
| Drive-by Compromise | T1189 | Watering-hole activity limited to selected visitors or networks | Proxy and browser telemetry, web-filter events, file origin, endpoint process lineage |
| Exploitation for Client Execution | T1203 | Exploitation of client-side vulnerabilities in historical campaigns | Application crashes, exploit-protection events, child processes, patch and asset state |
| Spearphishing Attachment | T1566.001 | Malicious document attachments in targeted campaigns | Email headers, attachment origin, sandbox results, endpoint execution chain, user report |
| User Execution: Malicious File | T1204.002 | User interaction with malicious files | File provenance, Mark-of-the-Web, process tree, script and macro controls |
| Ingress Tool Transfer | T1105 | Additional tools or malware transferred after access | Network egress, new files, proxy logs, EDR download and execution correlation |
| Process Discovery | T1057 | Process enumeration used to understand a host | Process creation and command-line telemetry interpreted against administrator baseline |
| Obfuscated Files: Steganography | T1027.003 | Executables concealed in image content in historical reporting | File-type mismatch, content inspection, memory execution, parent-child anomalies |
| Data from Local System | T1005 | Collection of files from compromised systems | File-access audit, archive creation, removable or staging paths, DLP and egress telemetry |
Publicly disclosed vulnerability exploitation also appears in Microsoft and joint-government reporting. Microsoft listed CVE-2021-44228, CVE-2023-46604, CVE-2023-22515, CVE-2023-27350, and CVE-2023-42793 among vulnerabilities used by Onyx Sleet in the observed period. Treat that list as evidence for exposure review, not as a permanent signature. A durable patch-management program must cover new exposed flaws, emergency decisions, compensating controls, and validation after remediation.
| Tool or family | Source-defined use | Defensive interpretation |
|---|---|---|
| Dtrack | Microsoft describes it as an Onyx Sleet RAT observed globally through January 2024 | Hunt for the behavior and access sequence; the family name alone does not prove the actor |
| TigerRAT | Custom remote-access malware used in campaigns since 2020 | Correlate remote command behavior, collection, process lineage, and network activity |
| SmallTiger | Backdoor used in 2024 targeting and referenced in GTIG's 2026 defense-sector review | Prioritize unusual memory execution, new services/tasks, identity use, and sensitive access |
| LightHand | Lightweight custom backdoor for command execution and file operations | Review shell lineage, file changes, endpoint connections, and subsequent credential activity |
| ValidAlpha / BlackRAT | Go-based backdoor reported against energy, defense, and engineering organizations | Treat as one family in a broader access chain, not a durable actor identifier |
| Dora RAT | Custom Go-based RAT documented in 2024 South Korean campaigns | Detect execution and network behavior; do not rely on one filename or certificate |
| Maui | Ransomware tied by U.S. allegations to healthcare extortion by an Andariel unit | Preserve encryption, account, process, payment, and impact evidence; coordinate legal and law enforcement |
| Sliver, RMM tools, proxies, and other public utilities | Microsoft and Mandiant report a mix of open-source, commercial, and public tools | Enforce approved-use policy and correlate tool use with user, device, destination, and change context |
Legitimate remote management, proxy, and system utilities can be used by administrators or attackers. DeepStrike's guide to living off the land explains why allowlisting a product name is weaker than baselining who launched it, from which parent process, on which device, under which identity, and toward which destination.
Static indicator lists decay quickly. They can support a time-bounded hunt, but this article intentionally does not republish IP addresses, domains, hashes, filenames, certificates, or wallet addresses. Defenders should retrieve current indicators from the original advisory or their trusted intelligence platform and retain the source date.
In July 2024, DOJ announced an indictment charging North Korean national Rim Jong Hyok with involvement in conspiracies to hack and extort U.S. hospitals, launder ransom proceeds, and fund additional intrusions. DOJ said the defendants were known in the private sector as Andariel, Onyx Sleet, and APT45, and alleged that Maui ransomware proceeds paid for infrastructure used against defense, technology, government, energy, and other targets. The DOJ Andariel case announcement also states plainly that an indictment is an allegation and defendants are presumed innocent unless proven guilty.
The legal announcement followed a 2022 investigation in which DOJ seized roughly half a million dollars connected to North Korean Maui ransomware and money laundering. Rapid reporting by a Kansas medical center helped investigators identify the then-new strain, trace payments, find another victim, seize funds, and support a joint advisory. The operational lesson is that timely reporting can create options beyond the victim's own recovery effort.
Mandiant's 2024 assessment uses a different evidentiary formulation: moderate confidence that APT45 engaged in ransomware development, but an inability to confirm APT45 attribution for every suspected ransomware cluster. Microsoft separately observed overlap between Onyx Sleet and Storm-0530, while saying H0lyGh0st ransomware use was unique to Storm-0530. Those distinctions should remain visible.
For healthcare leaders, the actor name should not eclipse patient-care risk. Segmentation, protected backups, recovery exercises, identity containment, downtime procedures, and law-enforcement contacts are more actionable than proving a vendor alias during the first hour. DeepStrike's current healthcare cybersecurity statistics can provide sector context without turning industry-wide figures into Andariel metrics.
Use the matrix to move from public reporting to testable evidence. It is an original DeepStrike decision aid, not an attribution standard.
| Public signal | Mission hypothesis | Observable behavior to validate | Decisive telemetry | Proportionate action |
|---|---|---|---|---|
| Exploitation alert on a public server | Shared access path for espionage or impact | Unexpected server child process, new access mechanism, outbound session, or privileged identity use | WAF, web and application logs, EDR, network flow, IdP, asset and patch records | Isolate or restrict the server, preserve volatile evidence, close exposure, review connected identities |
| Targeted job, research, or project lure | Strategic access or collection | File/link interaction followed by new process, session, token, or repository access | Email and collaboration logs, endpoint lineage, IdP, browser, source-control audit | Contain the device and session, rotate exposed secrets, investigate the relationship timeline |
| Remote tool or proxy on a sensitive host | Shared persistence or movement | Unapproved installation, unusual parent, off-hours use, new destination, or cross-segment access | EDR, software inventory, service/task logs, network flow, privileged-access records | Validate business use, suspend unauthorized access, scope related accounts and hosts |
| Bulk access to engineering or research data | Espionage collection | Unusual searches, archive staging, repository clones, large file reads, or external transfer | File audit, repository and cloud logs, DLP, endpoint, proxy, DNS, egress controls | Restrict access, preserve data-access evidence, determine scope and notification obligations |
| Encryption or sudden service disruption | Ransomware or destructive impact | Mass file changes, backup interference, service stops, ransom artifact, or recovery failure | EDR, file and server audit, identity, hypervisor, backup-console, recovery logs | Activate ransomware response, isolate affected segments, protect clean backups, coordinate legal and law enforcement |
| Both collection and encryption evidence | Dual-purpose intrusion | Staging or exfiltration before impact, plus privileged changes and encryption | Correlated endpoint, identity, network, storage, DLP, backup, and case timeline | Run data-breach and ransomware workstreams together; do not let recovery erase exfiltration evidence |
Two principles matter. First, early-stage behavior may not reveal the final mission, so preserve both espionage and impact evidence. Second, containment should address verified access before analysts debate sponsor attribution. The organization's own logs establish the incident; public intelligence frames hypotheses.
Maintain a current inventory of exposed services, versions, owners, dependencies, and business criticality. Correlate exploitation detections with server process creation, new files, outbound connections, authentication, and changes to applications or access mechanisms. A vulnerability scan alone cannot show whether exploitation occurred.
Collect process creation, command-line, file, module-load, script, service, scheduled-task, security-control, and network telemetry. Alert on unusual execution chains and remote tooling in context not merely the presence of a utility that administrators also use.
Centralize sign-ins, MFA events, token issuance and revocation, privileged-role changes, service-account use, remote access, and directory audit logs. Investigate sequences that connect a newly affected device or server to a high-value identity and a sensitive data source.
Preserve DNS, proxy, firewall, NetFlow, VPN, remote-access, and segmentation logs for a retention period that supports long-dwell investigations. Look for first-seen destinations, unusual encrypted sessions, proxy behavior, unexpected cross-segment access, and volume changes around sensitive systems.
Monitor repository clones, branch or workflow changes, package and artifact access, secrets, cloud storage, engineering file shares, and large archive creation. Defense and technology organizations should map crown-jewel projects to the identities, endpoints, suppliers, and services that can reach them.
Alert on mass file modification, backup policy changes, deletion or tampering, service interruption, unexpected hypervisor activity, and privileged access to recovery consoles. Recovery infrastructure needs separate credentials, restricted network paths, protected logs, and tested restore procedures.
An incident response plan should specify who can isolate a public server, revoke a privileged identity, protect evidence, pause sensitive operations, contact counsel, notify leadership, and engage government or specialist responders.
| Priority | Control | What to validate |
|---|---|---|
| 1 | Reduce exposed attack surface | Every internet-facing asset has an owner, supported version, patch SLA, access control, and logs |
| 2 | Patch exploited and high-risk flaws | Remediation is prioritized by exposure and exploitation evidence, then verified not merely marked complete |
| 3 | Segment public servers and sensitive data | A compromised edge or application server cannot directly reach identity control planes, backups, or crown-jewel repositories |
| 4 | Use phishing-resistant MFA and device-bound access | High-value accounts resist credential replay and unmanaged-device sessions |
| 5 | Govern remote administration tools | Approved tools, users, destinations, maintenance windows, and installation paths are explicit and monitored |
| 6 | Centralize protected telemetry | Identity, endpoint, server, network, cloud, repository, DLP, and backup logs survive endpoint compromise |
| 7 | Protect engineering and research data | Least privilege, project segmentation, DLP, repository controls, and external-sharing review cover sensitive programs |
| 8 | Build ransomware resilience | Backups are isolated, immutable where appropriate, monitored, and restored in realistic exercises |
| 9 | Rehearse dual-mission response | Teams can investigate exfiltration and restore operations without destroying evidence for either path |
| 10 | Validate controls under authorization | Testing uses written scope, safe rules of engagement, rollback plans, and remediation verification |
Organization-wide ransomware statistics can help explain business pressure, but they do not predict Andariel activity. Base control priorities on the organization's exposed services, sensitive data, critical operations, identity paths, and recovery dependencies.
Do not delay urgent containment while trying to prove an Andariel attribution. The July 2024 case also illustrates the value of early reporting: the FBI's current cyber guidance directs victims to report online crime promptly because rapid reporting can support investigation and potential recovery.
| Label | Typical public scope | Relationship to Andariel | Do not assume |
|---|---|---|---|
| Lazarus Group | Broad DPRK/RGB-linked umbrella covering espionage, disruption, theft, and strategic access | Treasury and MITRE place Andariel under or within it | Every Lazarus operation is Andariel |
| Bluenoroff / APT38 | Financially focused DPRK clusters associated with bank or cryptocurrency theft | Treasury described Bluenoroff as another Lazarus subgroup | Financial motivation makes it an Andariel alias |
| Storm-0530 / H0lyGh0st | Microsoft cluster associated with ransomware | Microsoft observed affiliations and tool/infrastructure overlap with Onyx Sleet | Overlap means one actor, or every H0lyGh0st case is Andariel |
| Kimsuky / APT43-related reporting | Separately tracked DPRK espionage activity with its own vendor boundaries | Same state nexus can create target and technique overlap | Every DPRK espionage lure belongs to Lazarus or Andariel |
| APT37 / ScarCruft-related reporting | Separately tracked DPRK espionage cluster | Separate public tracking despite geographic and sponsor overlap | Shared sponsorship proves shared operators or tooling |
This table is not a definitive organization chart. It is a writing and triage guardrail. DeepStrike's comparison of red teams and blue teams is also useful here: threat intelligence supplies hypotheses, defenders validate evidence, and authorized testing examines whether controls work without impersonating a real government's identity.
Andariel is just another name for every Lazarus operation. Public sources place it within the broader Lazarus ecosystem, but MITRE and vendors also track it separately.
APT45 and Onyx Sleet are perfect synonyms. They substantially overlap in public reporting, yet their vendors define and update their clusters independently.
Andariel is primarily a ransomware gang. Strategic espionage is central to the group's public history. Ransomware is a documented or assessed additional mission, not the whole entity.
Mandiant's caution disproves the U.S. government's ransomware claim. The sources use different cluster scopes, intelligence, and confidence language. Preserve both rather than forcing a false contradiction.
One malware family or CVE proves attribution. Tools, vulnerabilities, and ATT&CK techniques are shared across actors and legitimate administrators. Attribution needs a broader evidence set.
Old IOCs provide durable detection. Infrastructure and files change. Behavior, identity, exposure, process lineage, data access, and source-dated intelligence are more resilient.
Espionage is less urgent because it does not encrypt systems. Theft of military, engineering, nuclear, research, or source-code data can create strategic, contractual, safety, and downstream risks.
A penetration test can certify an organization as Andariel-proof. Testing evaluates a defined scope and time. It cannot guarantee resistance to a changing state-sponsored actor.
Andariel is a North Korean state-sponsored cyber threat group associated with the Reconnaissance General Bureau. MITRE tracks it as G0138, says it has operated since at least 2009, and considers it a subset of Lazarus Group. Public reporting connects it to espionage, destructive activity, cyber-enabled revenue, and ransomware-related operations.
Not exactly. U.S. Treasury and MITRE describe Andariel as a Lazarus subgroup or subset, while vendors often track its activity as a distinguishable cluster. “Lazarus Group” is also used as a broad umbrella, so an incident attributed to Lazarus should not automatically be relabeled Andariel.
Mandiant's APT45 and Microsoft's Onyx Sleet substantially overlap with activity reported as Andariel. The July 2024 joint advisory warns that vendor groupings may not match the U.S. government's scope 1:1. Use the source's original label and confidence instead of treating every alias as universally interchangeable.
U.S. authorities connect an Andariel unit to Maui ransomware attacks against healthcare organizations and allege that proceeds funded later espionage infrastructure. Mandiant assesses APT45 ransomware development with moderate confidence but does not confirm every suspected cluster. Andariel should therefore be described as an espionage actor with documented or assessed ransomware activity, not simply as a ransomware gang.
The strongest public reporting emphasizes defense, aerospace, nuclear, engineering, government, technology, energy, and healthcare. Other observed targets include manufacturing, construction, education, agriculture, pharmaceutical research, financial services, and selected online businesses. Sector similarity supports prioritization, not attribution by itself.
Public reporting associates Andariel-related clusters with Dtrack, TigerRAT, SmallTiger, LightHand, ValidAlpha, Dora RAT, Maui, and other custom tools, plus open-source and legitimate utilities. Tool presence alone does not prove the actor because malware can be shared, copied, repurposed, or misclassified.
Current public reporting supports continued relevance. In February 2026, GTIG said it had directly observed APT45 campaigns targeting people in defense organizations and identified a suspected APT45 SMALLTIGER operation. MITRE then modified the Andariel G0138 profile on July 31, 2026. These are dated observations, not a guarantee about every current campaign.
Andariel matters because its public record crosses boundaries that defenders often separate: strategic espionage and revenue, custom malware and legitimate tools, exposed services and targeted people, quiet collection and disruptive impact. Its labels also demonstrate why attribution must retain the source, date, scope, and confidence.
The durable defensive program is broader than an IOC list. Own and patch exposed systems, protect high-value identities and engineering data, govern remote tools, centralize endpoint and network telemetry, isolate recovery infrastructure, and rehearse a response that can investigate both exfiltration and encryption.
Where those risks match an organization's threat model, DeepStrike's penetration testing services can validate scoped internet-facing, internal, identity, cloud, and segmentation paths under written authorization and support remediation verification. The result is evidence about the tested scope and time not certification against Andariel or any named actor.
Author: Mohammed Khalil, CISSP, OSCP, OSWE
Last reviewed: August 26, 2026
Research verified through: August 26, 2026
Threat-actor naming, legal status, indicators, and active campaigns can change. Recheck the primary sources immediately before publication and before any material update.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us