Andariel

Actor Type Nation State
Attributed to Nation North Korea
Directly Linked Intrusion Sets Onyx Sleet , APT45
Associated Threat Actor North Korean Reconnaissance General Bureau 3rd Bureau
Associated MITRE ATT&CK Group Andariel (G0138)

Andariel is a state-sponsored cyber organization based in Pyongyang and Sinuiju, North Korea. It operates under the Reconnaissance General Bureau's (RGB) 3rd Bureau. Andariel has been active since around 2009 and focuses on espionage. Initially targeting defense contractors and military organizations, it has expanded its scope to include nuclear weapons information and, during the pandemic, organizations in the life sciences and pharmaceutical sector.

Andariel's primary objective is to steal sensitive and classified technical information, intellectual property, and military secrets. It has compromised organizations globally, seeking to further North Korea's military and nuclear ambitions. The group poses an ongoing threat to critical infrastructure organizations worldwide, including defense, financial services infrastructure, aerospace, nuclear, engineering, medical, and energy sectors.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

Andariel Threat Reports

Report

North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs

This cybersecurity advisory from the U.S. Federal Bureau of Investigation (FBI) and its partners, highlights the cyber espionage activities of the ...

References

MITRE ATT&CK Techniques

MITRE ATT&CK techniques observed in use by this intrusion set.