logo svg
logo

August 26, 2026

Updated: August 26, 2026

Andariel: Ransomware, Espionage, and North Korean Cyber Operations

How an RGB-linked actor combines strategic intelligence collection with a source-qualified ransomware mission

Mohammed Khalil

Mohammed Khalil

Featured Image

Andariel is frequently summarized as a North Korean hacking group, a Lazarus subgroup, an espionage actor, or a ransomware operator. Each description captures part of the public record, but none is precise enough by itself. The name sits inside overlapping government and vendor taxonomies, and those sources do not always assign the same activity with the same confidence.

For defenders, the useful question is not which alias wins. It is which behaviors have been credibly reported, what mission they may support, and which evidence would confirm that a similar path exists in the organization's own environment.

Executive Answer

Andariel is a North Korean state-sponsored threat group associated with the Reconnaissance General Bureau and active since at least 2009. MITRE tracks it as G0138 and considers it a subset of Lazarus Group, while Mandiant calls overlapping activity APT45 and Microsoft uses Onyx Sleet. Its core mission is strategic espionage against defense, aerospace, nuclear, engineering, government, and technology targets. U.S. authorities also connect an Andariel unit to Maui ransomware attacks on healthcare organizations, alleging that ransom proceeds funded later espionage. These labels overlap, but they are not automatically interchangeable.

Andariel at a Glance

QuestionEvidence-led answer
What is Andariel?A North Korean state-sponsored activity set associated with the Reconnaissance General Bureau
How long has it operated?Since at least 2009, according to MITRE and Mandiant
Is it part of Lazarus Group?MITRE and U.S. Treasury describe it as a subset or subgroup; other sources track it as a distinguishable cluster
Are APT45 and Onyx Sleet exact aliases?They substantially overlap with Andariel reporting, but source scopes are not guaranteed to match 1:1
What is its primary mission?Strategic intelligence collection, particularly against defense, aerospace, nuclear, engineering, and technology targets
Does it use ransomware?U.S. authorities connect an Andariel unit to Maui; Mandiant assesses ransomware involvement more cautiously for its APT45 cluster
What access paths recur?Exploitation of exposed software, targeted phishing, loaders/backdoors, credentials, remote tooling, and long-term collection
Is it still relevant in 2026?Yes; GTIG published fresh APT45 defense-sector observations in February 2026, and MITRE updated G0138 in July 2026

DeepStrike's broader Lazarus Group profile explains the umbrella label and its wider history. This article owns the narrower Andariel entity, its dual mission, and the evidence defenders need to distinguish an actor hypothesis from an incident fact.

Who Is Andariel?

MITRE ATT&CK describes Andariel as a North Korean state-sponsored threat group active since at least 2009. Its historical operations have included destructive attacks against South Korean government, military, and commercial organizations, along with financial activity affecting ATMs, banks, and cryptocurrency exchanges. MITRE assigns the group ID G0138 and describes it as a subset of Lazarus Group attributed to the Reconnaissance General Bureau. The profile was last modified July 31, 2026. See the current MITRE ATT&CK Andariel profile.

The U.S. Treasury took a policy and sanctions view in September 2019. It identified Andariel, Lazarus Group, and Bluenoroff as agencies, instrumentalities, or controlled entities of the North Korean government based on their relationship to the RGB. Treasury described Andariel as a Lazarus subgroup that conducted both revenue-generating cybercrime and intelligence collection, particularly against South Korean government and military targets. That is an official designation, not a complete technical organization chart.

Mandiant uses APT45 for a long-running cluster it assesses with high confidence to support North Korean state interests and with moderate confidence to be attributable specifically to the RGB. Its research traces activity to at least 2009 and emphasizes a relatively distinct malware lineage, shifting target priorities, and an unusual combination of espionage with suspected ransomware development. The Mandiant APT45 assessment is therefore close to, but not necessarily identical with, every use of “Andariel.”

The practical conclusion is narrow: Andariel is not merely a media nickname and not simply a malware family. It is an attribution label for a long-running North Korean activity set whose exact edges depend on the reporting source.

Andariel, APT45, Onyx Sleet, and Lazarus: The Naming Problem

Threat-actor names are analytical models. Governments, MITRE, and security vendors cluster evidence using different visibility, thresholds, time windows, and purposes. One source may group activity by sponsor or unit; another may split it by infrastructure, malware lineage, or victimology.

The July 2024 joint advisory made this limitation explicit. It said the cybersecurity industry uses overlapping names including Andariel, Onyx Sleet, and DarkSeoul for activity associated with the RGB 3rd Bureau, but warned that vendor groupings may not correlate 1:1 with the U.S. government's understanding. The NSA announcement for the joint advisory preserves that boundary.

LabelPrimary source using itWhat it representsSafe interpretation
AndarielMITRE, U.S. government, multiple vendorsNamed North Korean activity set; MITRE G0138Use for the entity when the source does, while retaining its scope and date
APT45Mandiant / GoogleVendor-defined DPRK operator clusterStrongly overlaps Andariel reporting; do not import every claim from another taxonomy automatically
Onyx SleetMicrosoftMicrosoft-defined North Korean actor clusterOverlaps Andariel/APT45; Microsoft also reports affiliations with other DPRK clusters
PLUTONIUMMicrosoft legacy namingEarlier Microsoft label associated with Onyx SleetHistorical vendor label, not a separate proof point
Silent ChollimaCrowdStrike and public reportingVendor activity label associated with AndarielPreserve source-specific scope
Stonefly / ClasiopaSymantec/Broadcom and public reportingVendor cluster associated with related activityOverlaps, but the matching boundary can vary by incident
Lazarus GroupGovernments, MITRE, vendors, mediaBroad actor or umbrella labelDo not replace every narrower DPRK cluster with “Lazarus”

Microsoft's own 2024 profile says other security companies track Onyx Sleet as APT45, Silent Chollima, Andariel, DarkSeoul, Stonefly, and TDrop2. It also reports operational overlap with Storm-0530, a separate cluster associated with H0lyGh0st ransomware. An observed relationship is not the same as identity, and a tool used by both does not collapse the groups into one.

The safest writing rule is simple: retain the original source's name, date, and confidence. For incident response, record three conclusions separately what happened, which technical cluster best fits, and which sponsor or unit a government or vendor attributes it to.

A Timeline of Andariel's Publicly Reported Evolution

PeriodPublic recordEvidence boundary
2009 onwardMITRE and Mandiant trace Andariel/APT45 activity to at least 2009An activity range, not a verified founding date
2015–2019Industry reporting increasingly separated Andariel from the broader Lazarus label; Treasury designated it in September 2019Treasury's subgroup framing is a policy attribution and may differ from vendor clustering
2019–2021Mandiant reports targeting related to nuclear, energy, agriculture, healthcare, defense, government, and financeTargeting changed with assessed DPRK priorities; not every sector appears in every campaign
2021–2022Public reporting connected suspected Andariel-related clusters with ransomware; U.S. agencies warned about North Korean use of Maui against healthcareThe 2022 advisory used a broad DPRK label; later 2024 legal and government reporting narrowed the Andariel connection
2023–June 2024Microsoft observed Onyx Sleet exploiting known vulnerabilities and using custom and public tools against defense, aerospace, manufacturing, education, construction, engineering, and energy targetsMicrosoft taxonomy; individual campaigns require their own attribution evidence
July 25, 2024A multinational advisory described the RGB 3rd Bureau's global espionage and ransomware funding; DOJ announced charges against Rim Jong HyokThe advisory is an assessment; the indictment contains allegations and is not a conviction
August–October 2024Symantec reported three U.S. private-sector intrusions it attributed to Stonefly and assessed as likely financially motivated; it saw no successful ransomware deploymentUseful continuity evidence, not proof of the intended final payload
February 10, 2026GTIG reported directly observing APT45 campaigns targeting defense-sector individuals and identified a suspected SMALLTIGER operationA current vendor observation; it does not make every job-themed approach APT45
July 31, 2026MITRE modified the Andariel G0138 profileConfirms a current knowledge-base review, not a new incident by itself

The 2019 Treasury action remains an important anchor because it publicly tied the Andariel label to the RGB and described both revenue and intelligence objectives. Its sanctions announcement should be read as dated official attribution, not as a permanent map of every North Korean intrusion set.

As of the August 26, 2026 research cutoff, the FBI still lists Rim Jong Hyok as wanted for alleged computer-hacking and promotion-money-laundering conspiracies. A wanted notice and indictment establish the government's allegation and current law-enforcement posture; they do not establish guilt.

What Are Andariel's Objectives?

Strategic Espionage

The joint advisory says the RGB 3rd Bureau primarily targets defense, aerospace, nuclear, and engineering organizations to obtain sensitive technical information and intellectual property that could advance North Korea's military and nuclear programs. It describes an ongoing threat to sectors worldwide, including organizations in the United States, South Korea, Japan, and India.

Mandiant's history adds government, energy, nuclear research, financial services, agriculture, healthcare, and pharmaceutical research. These targets should not be flattened into a generic “critical infrastructure” label. The likely value differs: military designs, engineering processes, energy information, scientific research, operational access, or funds.

In February 2026, Google Threat Intelligence Group said it had directly observed APT45, APT43, and UNC2970 campaigns targeting people at defense organizations. It also identified a suspected APT45 operation using SMALLTIGER against reported South Korean defense, semiconductor, and automotive manufacturing targets. The GTIG defense-industrial-base report makes personnel and hiring workflows part of the current defensive picture.

Revenue and Ransomware

The U.S. government's 2024 assessment goes beyond saying that a North Korean actor used ransomware. It links the RGB 3rd Bureau activity discussed in the advisory with ransomware operations against U.S. healthcare entities that funded espionage. DOJ alleged that Rim Jong Hyok and co-conspirators used Maui ransomware to extort healthcare providers, laundered the proceeds, and used funds to lease infrastructure for later intrusions against defense, technology, and government targets.

Mandiant is more cautious for its APT45 cluster. It assesses with moderate confidence that APT45 engaged in ransomware development, while stating that it could not confirm APT45 attribution for every ransomware-related cluster in public reporting. Both positions can coexist because the sources use different scopes and evidence.

The distinction matters. “Andariel uses ransomware” is supportable when tied to the U.S. government's narrower unit-level assessment and allegations. “Every Maui or H0lyGh0st incident is APT45” is not. “APT45 is primarily a ransomware gang” is also inaccurate because strategic collection is central to its public history.

DeepStrike's North Korean cryptocurrency operations analysis owns the broader DPRK financial-theft topic. Andariel's public revenue evidence should not be merged with every Lazarus- or BlueNoroff-linked cryptocurrency case.

Disruption and Optionality

MITRE notes destructive activity in Andariel's historical record. Access to a strategically valuable network can also create options: quiet collection now, broader access later, or disruptive impact if objectives change. Defenders should therefore protect confidentiality, integrity, and availability rather than assuming that espionage produces no operational risk.

Who Does Andariel Target?

Sector or assetWhy it may be valuableDefensive priority
Defense and aerospaceMilitary platforms, R&D, engineering data, suppliers, personnel, and project accessProtect identities, endpoints, repositories, collaboration systems, suppliers, and data egress
Nuclear and energyTechnical research, plant or engineering information, and strategic intelligenceSegment sensitive environments, control engineering-data access, and centralize identity and network logs
Government and militaryPolicy, operational, employee, and technical informationUse phishing-resistant MFA, privileged-access controls, and high-value-user monitoring
Technology and engineeringIntellectual property, software, designs, infrastructure, and trusted relationshipsPatch exposed systems, protect source and build systems, and monitor unusual bulk access
Healthcare and pharmaceuticalsRansomware impact, operational urgency, health research, and sensitive dataIsolate critical services, protect backups, rehearse downtime, and report incidents rapidly
Manufacturing, construction, and educationTechnical knowledge, supply-chain position, research, and opportunistic accessInventory exposed services, segment business units, and monitor remote tooling and data movement
Financial services and selected online businessesFunds, payment data, or revenue opportunitiesSeparate approvals, monitor anomalous transactions, and investigate identity-plus-endpoint sequences

The target list is an exposure model, not a prediction. A company in one of these sectors is not necessarily being targeted, and an intrusion in the sector is not automatically Andariel. DeepStrike's overview of state-sponsored hacking and APT threats provides the wider comparison context.

How Andariel Operations Develop

No single chain represents every campaign. Public reporting supports a set of recurring defensive possibilities:

  1. Target research and exposure discovery. Operators may identify internet-facing software, high-value organizations, projects, suppliers, or personnel.
  2. Initial access. Reported paths include exploitation of known vulnerabilities in exposed applications and targeted phishing or professional lures.
  3. Execution and foothold. Loaders, downloaders, web-access mechanisms, custom backdoors, or legitimate remote tools can establish continued access.
  4. Discovery and credentials. The actor may enumerate hosts, processes, users, network connections, software, and sensitive resources, then seek reusable identity material.
  5. Persistence and movement. Continued access can involve scheduled execution, remote services, proxies, credentials, or tools that resemble legitimate administration.
  6. Collection. Espionage paths can gather local files, engineering data, research, intellectual property, or repository content.
  7. Exfiltration or impact. A campaign may remove data, encrypt systems, extort a victim, or combine collection and disruption.
  8. Infrastructure change or re-entry. Closing one malware alert may not remove compromised identities, exposed services, third-party paths, or alternate footholds.

Recent Microsoft reporting shows why attack-surface management matters: Onyx Sleet has exploited multiple already disclosed vulnerabilities in internet-facing products. The lesson is not to hunt only those five CVEs forever; it is to maintain ownership, exposure, patch, and telemetry coverage for every public-facing service.

Selected MITRE ATT&CK Techniques and Defensive Telemetry

MITRE's G0138 profile is a historical, source-aggregated knowledge base. It is not a checklist guaranteed to appear in a current intrusion, and technique overlap cannot establish attribution.

TechniqueIDPublicly reported Andariel useHigh-value telemetry
Drive-by CompromiseT1189Watering-hole activity limited to selected visitors or networksProxy and browser telemetry, web-filter events, file origin, endpoint process lineage
Exploitation for Client ExecutionT1203Exploitation of client-side vulnerabilities in historical campaignsApplication crashes, exploit-protection events, child processes, patch and asset state
Spearphishing AttachmentT1566.001Malicious document attachments in targeted campaignsEmail headers, attachment origin, sandbox results, endpoint execution chain, user report
User Execution: Malicious FileT1204.002User interaction with malicious filesFile provenance, Mark-of-the-Web, process tree, script and macro controls
Ingress Tool TransferT1105Additional tools or malware transferred after accessNetwork egress, new files, proxy logs, EDR download and execution correlation
Process DiscoveryT1057Process enumeration used to understand a hostProcess creation and command-line telemetry interpreted against administrator baseline
Obfuscated Files: SteganographyT1027.003Executables concealed in image content in historical reportingFile-type mismatch, content inspection, memory execution, parent-child anomalies
Data from Local SystemT1005Collection of files from compromised systemsFile-access audit, archive creation, removable or staging paths, DLP and egress telemetry

Publicly disclosed vulnerability exploitation also appears in Microsoft and joint-government reporting. Microsoft listed CVE-2021-44228, CVE-2023-46604, CVE-2023-22515, CVE-2023-27350, and CVE-2023-42793 among vulnerabilities used by Onyx Sleet in the observed period. Treat that list as evidence for exposure review, not as a permanent signature. A durable patch-management program must cover new exposed flaws, emergency decisions, compensating controls, and validation after remediation.

Malware and Tools Associated With Andariel-Related Reporting

Tool or familySource-defined useDefensive interpretation
DtrackMicrosoft describes it as an Onyx Sleet RAT observed globally through January 2024Hunt for the behavior and access sequence; the family name alone does not prove the actor
TigerRATCustom remote-access malware used in campaigns since 2020Correlate remote command behavior, collection, process lineage, and network activity
SmallTigerBackdoor used in 2024 targeting and referenced in GTIG's 2026 defense-sector reviewPrioritize unusual memory execution, new services/tasks, identity use, and sensitive access
LightHandLightweight custom backdoor for command execution and file operationsReview shell lineage, file changes, endpoint connections, and subsequent credential activity
ValidAlpha / BlackRATGo-based backdoor reported against energy, defense, and engineering organizationsTreat as one family in a broader access chain, not a durable actor identifier
Dora RATCustom Go-based RAT documented in 2024 South Korean campaignsDetect execution and network behavior; do not rely on one filename or certificate
MauiRansomware tied by U.S. allegations to healthcare extortion by an Andariel unitPreserve encryption, account, process, payment, and impact evidence; coordinate legal and law enforcement
Sliver, RMM tools, proxies, and other public utilitiesMicrosoft and Mandiant report a mix of open-source, commercial, and public toolsEnforce approved-use policy and correlate tool use with user, device, destination, and change context

Legitimate remote management, proxy, and system utilities can be used by administrators or attackers. DeepStrike's guide to living off the land explains why allowlisting a product name is weaker than baselining who launched it, from which parent process, on which device, under which identity, and toward which destination.

Static indicator lists decay quickly. They can support a time-bounded hunt, but this article intentionally does not republish IP addresses, domains, hashes, filenames, certificates, or wallet addresses. Defenders should retrieve current indicators from the original advisory or their trusted intelligence platform and retain the source date.

What the Ransomware Evidence Actually Shows

In July 2024, DOJ announced an indictment charging North Korean national Rim Jong Hyok with involvement in conspiracies to hack and extort U.S. hospitals, launder ransom proceeds, and fund additional intrusions. DOJ said the defendants were known in the private sector as Andariel, Onyx Sleet, and APT45, and alleged that Maui ransomware proceeds paid for infrastructure used against defense, technology, government, energy, and other targets. The DOJ Andariel case announcement also states plainly that an indictment is an allegation and defendants are presumed innocent unless proven guilty.

The legal announcement followed a 2022 investigation in which DOJ seized roughly half a million dollars connected to North Korean Maui ransomware and money laundering. Rapid reporting by a Kansas medical center helped investigators identify the then-new strain, trace payments, find another victim, seize funds, and support a joint advisory. The operational lesson is that timely reporting can create options beyond the victim's own recovery effort.

Mandiant's 2024 assessment uses a different evidentiary formulation: moderate confidence that APT45 engaged in ransomware development, but an inability to confirm APT45 attribution for every suspected ransomware cluster. Microsoft separately observed overlap between Onyx Sleet and Storm-0530, while saying H0lyGh0st ransomware use was unique to Storm-0530. Those distinctions should remain visible.

For healthcare leaders, the actor name should not eclipse patient-care risk. Segmentation, protected backups, recovery exercises, identity containment, downtime procedures, and law-enforcement contacts are more actionable than proving a vendor alias during the first hour. DeepStrike's current healthcare cybersecurity statistics can provide sector context without turning industry-wide figures into Andariel metrics.

The DeepStrike Andariel Mission-to-Telemetry Matrix

Use the matrix to move from public reporting to testable evidence. It is an original DeepStrike decision aid, not an attribution standard.

Public signalMission hypothesisObservable behavior to validateDecisive telemetryProportionate action
Exploitation alert on a public serverShared access path for espionage or impactUnexpected server child process, new access mechanism, outbound session, or privileged identity useWAF, web and application logs, EDR, network flow, IdP, asset and patch recordsIsolate or restrict the server, preserve volatile evidence, close exposure, review connected identities
Targeted job, research, or project lureStrategic access or collectionFile/link interaction followed by new process, session, token, or repository accessEmail and collaboration logs, endpoint lineage, IdP, browser, source-control auditContain the device and session, rotate exposed secrets, investigate the relationship timeline
Remote tool or proxy on a sensitive hostShared persistence or movementUnapproved installation, unusual parent, off-hours use, new destination, or cross-segment accessEDR, software inventory, service/task logs, network flow, privileged-access recordsValidate business use, suspend unauthorized access, scope related accounts and hosts
Bulk access to engineering or research dataEspionage collectionUnusual searches, archive staging, repository clones, large file reads, or external transferFile audit, repository and cloud logs, DLP, endpoint, proxy, DNS, egress controlsRestrict access, preserve data-access evidence, determine scope and notification obligations
Encryption or sudden service disruptionRansomware or destructive impactMass file changes, backup interference, service stops, ransom artifact, or recovery failureEDR, file and server audit, identity, hypervisor, backup-console, recovery logsActivate ransomware response, isolate affected segments, protect clean backups, coordinate legal and law enforcement
Both collection and encryption evidenceDual-purpose intrusionStaging or exfiltration before impact, plus privileged changes and encryptionCorrelated endpoint, identity, network, storage, DLP, backup, and case timelineRun data-breach and ransomware workstreams together; do not let recovery erase exfiltration evidence

Two principles matter. First, early-stage behavior may not reveal the final mission, so preserve both espionage and impact evidence. Second, containment should address verified access before analysts debate sponsor attribution. The organization's own logs establish the incident; public intelligence frames hypotheses.

How to Detect Andariel-Related Behavior

Public-Facing Systems

Maintain a current inventory of exposed services, versions, owners, dependencies, and business criticality. Correlate exploitation detections with server process creation, new files, outbound connections, authentication, and changes to applications or access mechanisms. A vulnerability scan alone cannot show whether exploitation occurred.

Endpoint and Server Activity

Collect process creation, command-line, file, module-load, script, service, scheduled-task, security-control, and network telemetry. Alert on unusual execution chains and remote tooling in context not merely the presence of a utility that administrators also use.

Identity and Privileged Access

Centralize sign-ins, MFA events, token issuance and revocation, privileged-role changes, service-account use, remote access, and directory audit logs. Investigate sequences that connect a newly affected device or server to a high-value identity and a sensitive data source.

Network and Egress

Preserve DNS, proxy, firewall, NetFlow, VPN, remote-access, and segmentation logs for a retention period that supports long-dwell investigations. Look for first-seen destinations, unusual encrypted sessions, proxy behavior, unexpected cross-segment access, and volume changes around sensitive systems.

Sensitive Data and Developer Systems

Monitor repository clones, branch or workflow changes, package and artifact access, secrets, cloud storage, engineering file shares, and large archive creation. Defense and technology organizations should map crown-jewel projects to the identities, endpoints, suppliers, and services that can reach them.

Ransomware and Recovery Systems

Alert on mass file modification, backup policy changes, deletion or tampering, service interruption, unexpected hypervisor activity, and privileged access to recovery consoles. Recovery infrastructure needs separate credentials, restricted network paths, protected logs, and tested restore procedures.

An incident response plan should specify who can isolate a public server, revoke a privileged identity, protect evidence, pause sensitive operations, contact counsel, notify leadership, and engage government or specialist responders.

Mitigation Priorities

PriorityControlWhat to validate
1Reduce exposed attack surfaceEvery internet-facing asset has an owner, supported version, patch SLA, access control, and logs
2Patch exploited and high-risk flawsRemediation is prioritized by exposure and exploitation evidence, then verified not merely marked complete
3Segment public servers and sensitive dataA compromised edge or application server cannot directly reach identity control planes, backups, or crown-jewel repositories
4Use phishing-resistant MFA and device-bound accessHigh-value accounts resist credential replay and unmanaged-device sessions
5Govern remote administration toolsApproved tools, users, destinations, maintenance windows, and installation paths are explicit and monitored
6Centralize protected telemetryIdentity, endpoint, server, network, cloud, repository, DLP, and backup logs survive endpoint compromise
7Protect engineering and research dataLeast privilege, project segmentation, DLP, repository controls, and external-sharing review cover sensitive programs
8Build ransomware resilienceBackups are isolated, immutable where appropriate, monitored, and restored in realistic exercises
9Rehearse dual-mission responseTeams can investigate exfiltration and restore operations without destroying evidence for either path
10Validate controls under authorizationTesting uses written scope, safe rules of engagement, rollback plans, and remediation verification

Organization-wide ransomware statistics can help explain business pressure, but they do not predict Andariel activity. Base control priorities on the organization's exposed services, sensitive data, critical operations, identity paths, and recovery dependencies.

Incident Response Checklist

  1. Triage the behavior, not the brand. Record the initiating alert, affected asset, identity, time, and confirmed impact before assigning an actor.
  2. Preserve volatile and protected evidence. Capture relevant endpoint, server, network, identity, cloud, repository, backup, and security-tool records according to the response plan.
  3. Contain verified access. Restrict affected hosts, sessions, accounts, exposed services, and network paths while accounting for operational safety.
  4. Review identity scope. Revoke sessions and rotate passwords, tokens, keys, service credentials, and application secrets that the evidence places at risk.
  5. Hunt for alternate footholds. Examine related servers, remote tools, tasks, services, accounts, outbound infrastructure, and third-party paths.
  6. Run collection and impact workstreams together. Determine whether sensitive data was accessed or removed even if encryption is the visible event.
  7. Protect recovery. Confirm that clean backups, hypervisors, identity systems, and management consoles are separated from compromised credentials.
  8. Coordinate obligations. Engage legal, privacy, regulatory, insurance, sector, and law-enforcement contacts according to jurisdiction and impact.
  9. Validate eradication and restoration. Close the original exposure, remove persistence, rotate affected secrets, restore from trusted sources, and monitor for re-entry.
  10. Record attribution confidence separately. Maintain distinct findings for incident facts, technical cluster fit, sponsor attribution, and legal status.

Do not delay urgent containment while trying to prove an Andariel attribution. The July 2024 case also illustrates the value of early reporting: the FBI's current cyber guidance directs victims to report online crime promptly because rapid reporting can support investigation and potential recovery.

Andariel Compared With Nearby DPRK Labels

LabelTypical public scopeRelationship to AndarielDo not assume
Lazarus GroupBroad DPRK/RGB-linked umbrella covering espionage, disruption, theft, and strategic accessTreasury and MITRE place Andariel under or within itEvery Lazarus operation is Andariel
Bluenoroff / APT38Financially focused DPRK clusters associated with bank or cryptocurrency theftTreasury described Bluenoroff as another Lazarus subgroupFinancial motivation makes it an Andariel alias
Storm-0530 / H0lyGh0stMicrosoft cluster associated with ransomwareMicrosoft observed affiliations and tool/infrastructure overlap with Onyx SleetOverlap means one actor, or every H0lyGh0st case is Andariel
Kimsuky / APT43-related reportingSeparately tracked DPRK espionage activity with its own vendor boundariesSame state nexus can create target and technique overlapEvery DPRK espionage lure belongs to Lazarus or Andariel
APT37 / ScarCruft-related reportingSeparately tracked DPRK espionage clusterSeparate public tracking despite geographic and sponsor overlapShared sponsorship proves shared operators or tooling

This table is not a definitive organization chart. It is a writing and triage guardrail. DeepStrike's comparison of red teams and blue teams is also useful here: threat intelligence supplies hypotheses, defenders validate evidence, and authorized testing examines whether controls work without impersonating a real government's identity.

Common Misconceptions

Andariel is just another name for every Lazarus operation. Public sources place it within the broader Lazarus ecosystem, but MITRE and vendors also track it separately.

APT45 and Onyx Sleet are perfect synonyms. They substantially overlap in public reporting, yet their vendors define and update their clusters independently.

Andariel is primarily a ransomware gang. Strategic espionage is central to the group's public history. Ransomware is a documented or assessed additional mission, not the whole entity.

Mandiant's caution disproves the U.S. government's ransomware claim. The sources use different cluster scopes, intelligence, and confidence language. Preserve both rather than forcing a false contradiction.

One malware family or CVE proves attribution. Tools, vulnerabilities, and ATT&CK techniques are shared across actors and legitimate administrators. Attribution needs a broader evidence set.

Old IOCs provide durable detection. Infrastructure and files change. Behavior, identity, exposure, process lineage, data access, and source-dated intelligence are more resilient.

Espionage is less urgent because it does not encrypt systems. Theft of military, engineering, nuclear, research, or source-code data can create strategic, contractual, safety, and downstream risks.

A penetration test can certify an organization as Andariel-proof. Testing evaluates a defined scope and time. It cannot guarantee resistance to a changing state-sponsored actor.

Frequently Asked Questions

What is Andariel?

Andariel is a North Korean state-sponsored cyber threat group associated with the Reconnaissance General Bureau. MITRE tracks it as G0138, says it has operated since at least 2009, and considers it a subset of Lazarus Group. Public reporting connects it to espionage, destructive activity, cyber-enabled revenue, and ransomware-related operations.

Is Andariel the same as Lazarus Group?

Not exactly. U.S. Treasury and MITRE describe Andariel as a Lazarus subgroup or subset, while vendors often track its activity as a distinguishable cluster. “Lazarus Group” is also used as a broad umbrella, so an incident attributed to Lazarus should not automatically be relabeled Andariel.

Are APT45 and Onyx Sleet aliases for Andariel?

Mandiant's APT45 and Microsoft's Onyx Sleet substantially overlap with activity reported as Andariel. The July 2024 joint advisory warns that vendor groupings may not match the U.S. government's scope 1:1. Use the source's original label and confidence instead of treating every alias as universally interchangeable.

Does Andariel use ransomware?

U.S. authorities connect an Andariel unit to Maui ransomware attacks against healthcare organizations and allege that proceeds funded later espionage infrastructure. Mandiant assesses APT45 ransomware development with moderate confidence but does not confirm every suspected cluster. Andariel should therefore be described as an espionage actor with documented or assessed ransomware activity, not simply as a ransomware gang.

What sectors does Andariel target?

The strongest public reporting emphasizes defense, aerospace, nuclear, engineering, government, technology, energy, and healthcare. Other observed targets include manufacturing, construction, education, agriculture, pharmaceutical research, financial services, and selected online businesses. Sector similarity supports prioritization, not attribution by itself.

What malware does Andariel use?

Public reporting associates Andariel-related clusters with Dtrack, TigerRAT, SmallTiger, LightHand, ValidAlpha, Dora RAT, Maui, and other custom tools, plus open-source and legitimate utilities. Tool presence alone does not prove the actor because malware can be shared, copied, repurposed, or misclassified.

Is Andariel still active in 2026?

Current public reporting supports continued relevance. In February 2026, GTIG said it had directly observed APT45 campaigns targeting people in defense organizations and identified a suspected APT45 SMALLTIGER operation. MITRE then modified the Andariel G0138 profile on July 31, 2026. These are dated observations, not a guarantee about every current campaign.

Conclusion

Andariel matters because its public record crosses boundaries that defenders often separate: strategic espionage and revenue, custom malware and legitimate tools, exposed services and targeted people, quiet collection and disruptive impact. Its labels also demonstrate why attribution must retain the source, date, scope, and confidence.

The durable defensive program is broader than an IOC list. Own and patch exposed systems, protect high-value identities and engineering data, govern remote tools, centralize endpoint and network telemetry, isolate recovery infrastructure, and rehearse a response that can investigate both exfiltration and encryption.

Where those risks match an organization's threat model, DeepStrike's penetration testing services can validate scoped internet-facing, internal, identity, cloud, and segmentation paths under written authorization and support remediation verification. The result is evidence about the tested scope and time not certification against Andariel or any named actor.

Author and Review Information

Author: Mohammed Khalil, CISSP, OSCP, OSWE

Last reviewed: August 26, 2026

Research verified through: August 26, 2026

Threat-actor naming, legal status, indicators, and active campaigns can change. Recheck the primary sources immediately before publication and before any material update.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us