Andariel
Also reported as Onyx Sleet, Silent Chollima, PLUTONIUM, Sapphire Sleet, Black Artemis and 77 other names. Linked to North Korea by four sources.
Reports per quarter
Techniques seen in the last two years
- T1190 3 reports reports only
- T1566.001 3 reports in ATT&CK
- T1021 2 reports reports only
- T1021.002 2 reports reports only
- T1027 2 reports reports only
- T1039 2 reports reports only
- T1040 2 reports reports only
- T1053.005 2 reports reports only
- T1059 2 reports reports only
- T1059.001 2 reports reports only
Show all 244 techniques Show fewer
- T1059.005 2 reports reports only
- T1071 2 reports reports only
- T1083 2 reports reports only
- T1087 2 reports reports only
- T1090 2 reports reports only
- T1091 2 reports reports only
- T1140 2 reports reports only
- T1195 2 reports reports only
- T1518.001 2 reports reports only
- T1560 2 reports reports only
- T1566.002 2 reports reports only
- T1566.003 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1572 2 reports reports only
- T1595 2 reports reports only
- T1003 1 report reports only
- T1005 1 report in ATT&CK
- T1007 1 report reports only
- T1008 1 report reports only
- T1010 1 report reports only
- T1012 1 report reports only
- T1016 1 report reports only
- T1016.001 1 report reports only
- T1018 1 report reports only
- T1020 1 report reports only
- T1021.001 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1033 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1041 1 report reports only
- T1046 1 report reports only
- T1047 1 report reports only
- T1048 1 report reports only
- T1049 1 report in ATT&CK
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055 1 report reports only
- T1055.001 1 report reports only
- T1055.002 1 report reports only
- T1055.003 1 report reports only
- T1055.004 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1056.001 1 report reports only
- T1057 1 report in ATT&CK
- T1059.002 1 report reports only
- T1059.003 1 report reports only
- T1059.004 1 report reports only
- T1059.006 1 report reports only
- T1059.007 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1068 1 report reports only
- T1069 1 report reports only
- T1069.001 1 report reports only
- T1069.002 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.004 1 report reports only
- T1071.001 1 report reports only
- T1071.004 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078 1 report reports only
- T1078.004 1 report reports only
- T1082 1 report reports only
- T1087.001 1 report reports only
- T1087.002 1 report reports only
- T1087.004 1 report reports only
- T1090.001 1 report reports only
- T1090.003 1 report reports only
- T1095 1 report reports only
- T1098 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1098.007 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1104 1 report reports only
- T1105 1 report in ATT&CK
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1119 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1124 1 report reports only
- T1125 1 report reports only
- T1129 1 report reports only
- T1132 1 report reports only
- T1132.001 1 report reports only
- T1133 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1135 1 report reports only
- T1136 1 report reports only
- T1136.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1189 1 report in ATT&CK
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report in ATT&CK
- T1204 1 report reports only
- T1204.001 1 report reports only
- T1204.002 1 report in ATT&CK
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1217 1 report reports only
- T1219 1 report reports only
- T1482 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1486 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1496 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1505 1 report reports only
- T1505.003 1 report reports only
- T1505.004 1 report reports only
- T1518 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.003 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.001 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1554 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1557 1 report reports only
- T1559 1 report reports only
- T1560.001 1 report reports only
- T1560.002 1 report reports only
- T1564.001 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566 1 report reports only
- T1566.004 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1573 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583 1 report reports only
- T1583.003 1 report reports only
- T1584 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1587 1 report reports only
- T1587.001 1 report reports only
- T1587.003 1 report reports only
- T1587.004 1 report reports only
- T1588 1 report reports only
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1591 1 report reports only
- T1592 1 report reports only
- T1595.002 1 report reports only
- T1596 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608 1 report reports only
- T1608.001 1 report reports only
- T1608.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1608.006 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2010-0232 KEV
- CVE-2010-4398 KEV
- CVE-2011-1255
- CVE-2011-3402 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1889 KEV
- CVE-2013-0640 KEV
- CVE-2013-3893 KEV
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-4979
Show all 227 CVEs Show fewer
- CVE-2014-0497 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-6332 KEV
- CVE-2014-8439 KEV
- CVE-2015-0235
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2360 KEV
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2545 KEV
- CVE-2015-3105
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7547
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0189 KEV ransomware
- CVE-2016-0545
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7256 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-18368 KEV
- CVE-2017-4946
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-8291 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2025036
- CVE-2018-4878 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0703 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1069 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-15637
- CVE-2019-1579 KEV ransomware
- CVE-2019-16759 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-5591 KEV ransomware
- CVE-2019-7609 KEV
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-12812 KEV ransomware
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20028 KEV ransomware
- CVE-2021-20038 KEV ransomware
- CVE-2021-21551 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-3018
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-31955 KEV
- CVE-2021-31956 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-35394 KEV
- CVE-2021-36955 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40684
- CVE-2021-4104
- CVE-2021-41773 KEV ransomware
- CVE-2021-43226 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44142
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2021-45837
- CVE-2022-0609 KEV
- CVE-2022-1040 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-20821 KEV
- CVE-2022-21882 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22005
- CVE-2022-22947 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-22972
- CVE-2022-24663
- CVE-2022-24664
- CVE-2022-24665
- CVE-2022-24785
- CVE-2022-24990 KEV ransomware
- CVE-2022-25064
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26352 KEV ransomware
- CVE-2022-26871 KEV
- CVE-2022-27518 KEV
- CVE-2022-27925 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-28810 KEV
- CVE-2022-29499 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-34305
- CVE-2022-37042 KEV ransomware
- CVE-2022-40139 KEV
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-41128 KEV
- CVE-2022-41328 KEV
- CVE-2022-41352 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-44698 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-21932
- CVE-2023-23397 KEV
- CVE-2023-25690
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-3079 KEV
- CVE-2023-32315 KEV
- CVE-2023-32784
- CVE-2023-33010 KEV
- CVE-2023-33246 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-35078 KEV ransomware
- CVE-2023-3519 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46604 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-0012 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-26229
- CVE-2024-3400 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9474 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-0282 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-1281 KEV
- CVE-2026-1340 KEV
- CVE-2026-21509 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 301 reports Show fewer
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
Subgroup: Bluenoroff, APT 38, Stardust Chollima
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Subgroup: Bluenoroff, APT 38, Stardust Chollima
-
Subgroup: Andariel, Silent Chollima - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Subgroup: Andariel, Silent Chollima - Threat Group Cards: A Threat Actor Encyclopedia
-
New Andariel Reconnaissance Tactics Uncovered
The original link failed its last check. Original publisher Detailsfor New Andariel Reconnaissance Tactics Uncovered
-
Subgroup: BeagleBoyz - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Subgroup: BeagleBoyz - Threat Group Cards: A Threat Actor Encyclopedia
-
Lazarus Group, Hidden Cobra, Labyrinth Chollima
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Lazarus Group, Hidden Cobra, Labyrinth Chollima
-
100DaysofYARA - SpectralBlur | A Clever Blog Name by Greg Lesnewich
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 100DaysofYARA - SpectralBlur | A Clever Blog Name by Greg Lesnewich
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Objective-See's Blog
-
Lazarus supply-chain attack in South Korea
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Lazarus supply-chain attack in South Korea
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Bluenoroff’s RustBucket campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bluenoroff’s RustBucket campaign
-
Andariel’s “Jupiter” malware and the case of the curious C2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Andariel’s “Jupiter” malware and the case of the curious C2
-
Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Stealing the LIGHTSHOW (Part One) - North Korea's UNC2970
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Stealing the LIGHTSHOW (Part One) - North Korea's UNC2970
-
Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970
-
TA444- The APT Startup Aimed at Acquisition (of Your Funds)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA444- The APT Startup Aimed at Acquisition (of Your Funds)
-
Emulating the Highly Sophisticated North Korean Adversary Lazarus Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emulating the Highly Sophisticated North Korean Adversary Lazarus Group
-
The DPRK delicate sound of cyber
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The DPRK delicate sound of cyber
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Report
-
Hunting for Unsigned DLLs to Find APTs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting for Unsigned DLLs to Find APTs
-
Andariel deploys DTrack and Maui ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Andariel deploys DTrack and Maui ransomware
-
North Korean H0lyGh0st Ransomware Has Ties to Global Geopolitics
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean H0lyGh0st Ransomware Has Ties to Global Geopolitics
-
LofyLife- malicious npm packages steal Discord tokens and bank card data
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LofyLife- malicious npm packages steal Discord tokens and bank card data
-
Anatomy of Attack- Truth Behind the Costa Rica Government Ransomware 5-Day Intrusion
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anatomy of Attack- Truth Behind the Costa Rica Government Ransomware 5-Day Intrusion
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean threat actor (H0lyGh0st -DEV-0530) targets small and midsize businesses with H0lyGh0st ransomware
-
Hydra with Three Heads- BlackByte & The Future of Ransomware Subsidiary Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hydra with Three Heads- BlackByte & The Future of Ransomware Subsidiary Groups
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
An Overview of the Increasing Wiper Malware Threat
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Overview of the Increasing Wiper Malware Threat
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
Stonefly- North Korea-linked Spying Operation Continues to Hit High-value Targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Stonefly- North Korea-linked Spying Operation Continues to Hit High-value Targets
-
Stonefly: North Korea-linked Spying Operation Continues to Hit High-value Targets
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Stonefly: North Korea-linked Spying Operation Continues to Hit High-value Targets
-
Enter KaraKurt- Data Extortion Arm of Prolific Ransomware Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Enter KaraKurt- Data Extortion Arm of Prolific Ransomware Group
-
North Korea- Intelligence Assessment 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korea- Intelligence Assessment 2022
-
Countering threats from North Korea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Countering threats from North Korea
-
Not So Lazarus- Mapping DPRK Cyber Threat Groups to Government Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Not So Lazarus- Mapping DPRK Cyber Threat Groups to Government Organizations
-
Establishing the TigerRAT and TigerDownloader malware families
The original link failed its last check. Original publisher Detailsfor Establishing the TigerRAT and TigerDownloader malware families
-
Nowhere to Hide- Detecting SILENT CHOLLIMA’s Custom Tooling
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Nowhere to Hide- Detecting SILENT CHOLLIMA’s Custom Tooling
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
APT_trends_report_Q2_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2021_Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2021ThreatHunting
-
filedownload.do?attach_file_seq=3277&attach_file_id=EpF3277.pdf
The original link failed its last check. Original publisher Detailsfor filedownload.do?attach_file_seq=3277&attach_file_id=EpF3277.pdf
-
North Korean Cyberattacks A Dangerous and Evolving Threat 2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean Cyberattacks A Dangerous and Evolving Threat 2
-
The Incredible Rise of DPRK’s Cyber Warfare
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Incredible Rise of DPRK’s Cyber Warfare
-
Secret -Backdoor- Behind Conti Ransomware Operation- Introducing Atera Agent
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Secret -Backdoor- Behind Conti Ransomware Operation- Introducing Atera Agent
-
InSideCopy: How this APT continues to evolve its arsenal
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
Ransomware-&-CVE- Industry Insights Into Exclusive High-Value Target Adversarial Datasets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware-&-CVE- Industry Insights Into Exclusive High-Value Target Adversarial Datasets
-
Andariel evolves to target South Korea with ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Andariel evolves to target South Korea with ransomware
-
From QBot...with REvil Ransomware- Initial Attack Exposure of JBS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From QBot...with REvil Ransomware- Initial Attack Exposure of JBS
-
Rising warning- APT organizes Lazarus Group to launch an attack on China
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rising warning- APT organizes Lazarus Group to launch an attack on China
-
From Dawn to -Silent Night-- -DarkSide Ransomware- Initial Attack Vector Evolution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor From Dawn to -Silent Night-- -DarkSide Ransomware- Initial Attack Vector Evolution
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CryptoCore-Lazarus-Clearsky
-
Adversary Dossier- Ryuk Ransomware Anatomy of an Attack in 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Adversary Dossier- Ryuk Ransomware Anatomy of an Attack in 2021
-
Lazarus BTC Changer Back in action with JS sniffers redesigned to steal crypto
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lazarus BTC Changer Back in action with JS sniffers redesigned to steal crypto
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
kaspersky-ics-cert-lazarus-targets-defense-industry-with-threatneedle-en-20210225
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor kaspersky-ics-cert-lazarus-targets-defense-industry-with-threatneedle-en-20210225
-
Lazarus targets defense industry with ThreatNeedle
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lazarus targets defense industry with ThreatNeedle
-
钱包黑洞:Lazarus 组织近期在加密货币方面的隐蔽攻击活动
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 钱包黑洞:Lazarus 组织近期在加密货币方面的隐蔽攻击活动
-
Hacking Farm to Table- Threat Hunters Uncover Rise in Attacks Against Agriculture
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hacking Farm to Table- Threat Hunters Uncover Rise in Attacks Against Agriculture
-
Lazarus supply‑chain attack in South Korea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lazarus supply‑chain attack in South Korea
-
The many personalities of Lazarus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The many personalities of Lazarus
-
The BLINDINGCAN RAT and Malicious North Korean Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The BLINDINGCAN RAT and Malicious North Korean Activity
-
CryptoCore – Cryptocurrency Exchanges Under Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CryptoCore – Cryptocurrency Exchanges Under Attack
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ASEC_REPORT_vol.98_ENG
-
Lexfo-WhitePaper-The_Lazarus_Constellation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lexfo-WhitePaper-The_Lazarus_Constellation
-
DPRK Hidden Cobra Update- North Korean Malicious Cyber Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DPRK Hidden Cobra Update- North Korean Malicious Cyber Activity
-
The ICS Threat Landscape and Activity Groups
The original link failed its last check. Original publisher Detailsfor The ICS Threat Landscape and Activity Groups
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation AppleJeus Sequel
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation AppleJeus Sequel
-
North American Electric Cyber Threat Perspective
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North American Electric Cyber Threat Perspective
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lazarus Group Goes 'Fileless'
-
Operation ENDTRADE: Multi-Stage Backdoors that TICK
The original link failed its last check. Original publisher Detailsfor Operation ENDTRADE: Multi-Stage Backdoors that TICK
-
Wikipedia Entry on Equation Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wikipedia Entry on Equation Group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Let's Learn- Dissecting Lazarus Windows x86 Loader Involved in Crypto Trading App Distribution- -snowman- & ADVObfuscator
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pass the AppleJeus
-
The original link failed its last check. Original publisher Detailsfor [Analysis]Andariel_Group.pdf
-
Dragos - Global Oil and Gas Cyber Threat Perspctive
The original link failed its last check. Original publisher Detailsfor Dragos - Global Oil and Gas Cyber Threat Perspctive
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Cryptocurrency businesses still being targeted by Lazarus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cryptocurrency businesses still being targeted by Lazarus
-
Daily Ruleset Update Summary 2019-03-14
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Daily Ruleset Update Summary 2019-03-14
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The Advanced Persistent Threat files- Lazarus Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Advanced Persistent Threat files- Lazarus Group
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
yir-ics-activity-groups-threat-landscape-2018.pdf
The original link failed its last check. Original publisher Detailsfor yir-ics-activity-groups-threat-landscape-2018.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-apt38-2018-web_v4
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation_AppleJeus
-
Operation AppleJeus- Lazarus hits cryptocurrency exchange with fake installer and macOS malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation AppleJeus- Lazarus hits cryptocurrency exchange with fake installer and macOS malware
-
Lazarus Group Deploys Its First Mac Malware in Cryptocurrency Exchange Hack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lazarus Group Deploys Its First Mac Malware in Cryptocurrency Exchange Hack
-
Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families | McAfee Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Examining Code Reuse Reveals Undiscovered Links Among North Korea’s Malware Families | McAfee Blogs
-
New Andariel Reconnaissance Tactics Hint At Next Targets - TrendLabs Security Intelligence Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Andariel Reconnaissance Tactics Hint At Next Targets - TrendLabs Security Intelligence Blog
-
Full Discloser of Andariel, A Subgroup of Lazarus Threat Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Full Discloser of Andariel, A Subgroup of Lazarus Threat Group
-
Dissecting Operation Troy: Cyberespionage in South Korea White Paper
The original link failed its last check. Original publisher Detailsfor Dissecting Operation Troy: Cyberespionage in South Korea White Paper
-
North Korean Hackers Are up to No Good Again
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean Hackers Are up to No Good Again
-
Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide
-
Analyzing Operation GhostSecret- Attack Seeks to Steal Data Worldwide
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Operation GhostSecret- Attack Seeks to Steal Data Worldwide
-
Industrial Control System Threats
The original link failed its last check. Original publisher Detailsfor Industrial Control System Threats
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attacks Leveraging Adobe Zero-Day (CVE-2018-4878) – Threat Attribution, Attack Scenario and Recommendations
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North Korea Is Not Crazy
-
The original link failed its last check. Original publisher Detailsfor 2017 HITB A Deep Dive_release
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor North Korea Is Not Crazy
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Lazarus
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor The Blockbuster Sequel
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Blockbuster Sequel
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OurMine
-
Bartholomew-GuerreroSaade-VB2016.indd
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bartholomew-GuerreroSaade-VB2016.indd
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Shadow Brokers
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
Tracing the Lineage of DarkSeoul
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracing the Lineage of DarkSeoul
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Blockbuster
-
Russian Police Prevented Massive Banking Sector Cyber Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Police Prevented Massive Banking Sector Cyber Attack
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
TDrop2 Attacks Suggest Dark Seoul Attackers Return - Palo Alto Networks BlogPalo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TDrop2 Attacks Suggest Dark Seoul Attackers Return - Palo Alto Networks BlogPalo Alto Networks Blog
-
WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
-
Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hacking Team
-
Cisco - Annual Security Report - 2014.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco - Annual Security Report - 2014.pdf
-
World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
-
CrowdCasts Monthly- You Have an Adversary Problem
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdCasts Monthly- You Have an Adversary Problem
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
Dissecting Operation Troy: Cyberespionage In South Korea
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dissecting Operation Troy: Cyberespionage In South Korea
-
Dark Seoul Cyber Attack: Could It Be Worse?
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Dark Seoul Cyber Attack: Could It Be Worse?
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dark_Seoul_Cyberattack
-
Four Years of DarkSeoul Cyberattacks Against South Korea Continue on Anniversary of Korean War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Four Years of DarkSeoul Cyberattacks Against South Korea Continue on Anniversary of Korean War
-
Four Years of DarkSeoul Cyberattacks Against South Korea Continue on Anniversary of Korean War
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Four Years of DarkSeoul Cyberattacks Against South Korea Continue on Anniversary of Korean War
-
Fidelis Threat Advisory 1008 - Darkseoul-Jokra Analysis and Recovery
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Fidelis Threat Advisory 1008 - Darkseoul-Jokra Analysis and Recovery
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PLA Unit 61398
-
“Red October” – Part Two, the Modules
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Red October” – Part Two, the Modules
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Syrian Electronic Army
Newest first. Details opens the report in Explore.