All actors

Andariel

Also reported as Onyx Sleet, Silent Chollima, PLUTONIUM, Sapphire Sleet, Black Artemis and 77 other names. Linked to North Korea by four sources.

Reports
301
Last reported
Known CVEs
227
Techniques in ATT&CK
12
Origin
North Korea
ID
G0138
Merge evidence
64 alias matches

Reports per quarter

  1. 2012 Q3: 1 report
  2. 2012 Q4: no reports
  3. 2013 Q1: 3 reports
  4. 2013 Q2: 4 reports
  5. 2013 Q3: 1 report
  6. 2013 Q4: 3 reports
  7. 2014 Q1: 1 report
  8. 2014 Q2: 1 report
  9. 2014 Q3: 2 reports
  10. 2014 Q4: no reports
  11. 2015 Q1: no reports
  12. 2015 Q2: no reports
  13. 2015 Q3: no reports
  14. 2015 Q4: 1 report
  15. 2016 Q1: 7 reports
  16. 2016 Q2: 1 report
  17. 2016 Q3: 2 reports
  18. 2016 Q4: no reports
  19. 2017 Q1: 2 reports
  20. 2017 Q2: 6 reports
  21. 2017 Q3: 1 report
  22. 2017 Q4: 1 report
  23. 2018 Q1: 5 reports
  24. 2018 Q2: 6 reports
  25. 2018 Q3: 8 reports
  26. 2018 Q4: 4 reports
  27. 2019 Q1: 9 reports
  28. 2019 Q2: 2 reports
  29. 2019 Q3: 5 reports
  30. 2019 Q4: 9 reports
  31. 2020 Q1: 12 reports
  32. 2020 Q2: 5 reports
  33. 2020 Q3: 6 reports
  34. 2020 Q4: 8 reports
  35. 2021 Q1: 6 reports
  36. 2021 Q2: 12 reports
  37. 2021 Q3: 7 reports
  38. 2021 Q4: 10 reports
  39. 2022 Q1: 3 reports
  40. 2022 Q2: 10 reports
  41. 2022 Q3: 19 reports
  42. 2022 Q4: 5 reports
  43. 2023 Q1: 19 reports
  44. 2023 Q2: 6 reports
  45. 2023 Q3: 5 reports
  46. 2023 Q4: 6 reports
  47. 2024 Q1: 3 reports
  48. 2024 Q2: 8 reports
  49. 2024 Q3: 2 reports
  50. 2024 Q4: 1 report
  51. 2025 Q1: 2 reports
  52. 2025 Q2: 5 reports
  53. 2025 Q3: 1 report
  54. 2025 Q4: 2 reports
  55. 2026 Q1: 5 reports
  56. 2026 Q2: 45 reports
  57. 2026 Q3: 3 reports
Dated reports, 2012 Q3 to 2026 Q3.

Techniques seen in the last two years

Show all 244 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 227 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

Show all 301 reports Show fewer
  1. CrowdCasts Monthly: You Have an Adversary Problem

    date ORKL added it fromORKL

  2. Subgroup: Bluenoroff, APT 38, Stardust Chollima

    date ORKL added it fromORKL

  3. Lazarus Group, Hidden Cobra, Labyrinth Chollima

    date ORKL added it fromORKL

  4. Objective-See's Blog

    file creation date fromORKL

  5. Lazarus supply-chain attack in South Korea

    file creation date ESET fromORKL

  6. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  7. Bluenoroff’s RustBucket campaign

    date in the title fromORKL

  8. The DPRK delicate sound of cyber

    date in the title fromORKL

  9. Operation-Blockbuster-Report

    date ORKL added it fromORKL

  10. Hunting for Unsigned DLLs to Find APTs

    date in the title fromORKL

  11. Andariel deploys DTrack and Maui ransomware

    date in the title fromORKL

  12. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  13. An Overview of the Increasing Wiper Malware Threat

    date in the title fromORKL

  14. yir-cyber-threats-report-download.pdf

    Malpedia library date fromORKL

  15. North Korea- Intelligence Assessment 2022

    date in the title fromORKL

  16. Countering threats from North Korea

    date in the title fromORKL

  17. APT trends report Q3 2021

    date in the title fromORKL

  18. APT_trends_report_Q2_2021_Securelist

    file creation date fromORKL

  19. Report2021ThreatHunting

    file creation date fromORKL

  20. North Korean Cyberattacks A Dangerous and Evolving Threat 2

    date in the CCS '25 data Heritage.org fromORKLCCS '25 data

  21. The Incredible Rise of DPRK’s Cyber Warfare

    date in the title fromORKL

  22. InSideCopy: How this APT continues to evolve its arsenal

    Malpedia library date Talos fromORKL

  23. Andariel evolves to target South Korea with ransomware

    date in the title fromORKL

  24. CryptoCore-Lazarus-Clearsky

    Malpedia library date Kaspersky fromORKLCCS '25 data

  25. mtrends-2021

    file creation date fromORKL

  26. kaspersky-ics-cert-lazarus-targets-defense-industry-with-threatneedle-en-20210225

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  27. Lazarus targets defense industry with ThreatNeedle

    date in the title fromORKL

  28. Lazarus supply‑chain attack in South Korea

    date in the title fromORKL

  29. The many personalities of Lazarus

    date in the title fromORKL

  30. The BLINDINGCAN RAT and Malicious North Korean Activity

    date in the title fromORKL

  31. CryptoCore – Cryptocurrency Exchanges Under Attack

    date in the title fromORKL

  32. ASEC_REPORT_vol.98_ENG

    date in the CCS '25 data AhnLab fromORKLCCS '25 data

  33. Lexfo-WhitePaper-The_Lazarus_Constellation

    file creation date fromORKL

  34. Operation AppleJeus Sequel

    date in the title fromORKL

  35. Operation AppleJeus Sequel

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  36. North American Electric Cyber Threat Perspective

    Malpedia library date fromORKL

  37. Lazarus Group Goes 'Fileless'

    date in the title fromORKL

  38. Wikipedia Entry on Equation Group

    date in the title fromORKL

  39. Pass the AppleJeus

    date in the title fromORKL

  40. [Analysis]Andariel_Group.pdf

    file creation date fromORKL

  41. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  42. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  43. Cryptocurrency businesses still being targeted by Lazarus

    date in the title fromORKL

  44. Daily Ruleset Update Summary 2019-03-14

    date in the title fromORKL

  45. Report2019GlobalThreatReport

    file creation date fromORKL

  46. The Advanced Persistent Threat files- Lazarus Group

    date in the title fromORKL

  47. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  48. rpt-apt38-2018-web_v4

    file creation date fromORKL

  49. Operation_AppleJeus

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  50. Full Discloser of Andariel, A Subgroup of Lazarus Threat Group

    Malpedia library date AhnLab fromORKLCCS '25 data

  51. North Korean Hackers Are up to No Good Again

    date in the title fromORKL

  52. Industrial Control System Threats

    Malpedia library date Dragos fromORKL

  53. North Korea Is Not Crazy

    file creation date fromORKL

  54. 2017 HITB A Deep Dive_release

    file creation date fromORKL

  55. North Korea Is Not Crazy

    date in the CCS '25 data Recorded Future fromORKLCCS '25 data

  56. Group-IB_Lazarus

    Malpedia library date Group-IB fromORKLCCS '25 data

  57. The Blockbuster Sequel

    date in the CCS '25 data Palo Alto Networks fromORKLCCS '25 data

  58. The Blockbuster Sequel

    date in the title fromORKL

  59. OurMine

    date in the title fromORKL

  60. Bartholomew-GuerreroSaade-VB2016.indd

    Malpedia library date Kaspersky fromORKL

  61. The Shadow Brokers

    date in the title fromORKL

  62. PowerPoint Presentation

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  63. Tracing the Lineage of DarkSeoul

    date in the title fromORKL

  64. Operation Blockbuster

    date in the CCS '25 data Novetta fromORKLCCS '25 data

  65. Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape

    date in the CCS '25 data HP fromORKLCCS '25 data

  66. Hacking Team

    date in the title fromORKL

  67. Cisco - Annual Security Report - 2014.pdf

    file creation date fromORKL

  68. CrowdCasts Monthly- You Have an Adversary Problem

    date in the title fromORKL

  69. CrowdCasts Monthly: You Have an Adversary Problem

    Malpedia library date fromORKL

  70. Dissecting Operation Troy: Cyberespionage In South Korea

    file creation date McAfee fromORKL

  71. Dark Seoul Cyber Attack: Could It Be Worse?

    file creation date Dongseo University fromORKL

  72. Dark_Seoul_Cyberattack

    file creation date fromORKL

  73. PLA Unit 61398

    date in the title fromORKL

  74. “Red October” – Part Two, the Modules

    date in the title fromORKL

  75. Syrian Electronic Army

    date in the title fromORKL

Newest first. Details opens the report in Explore.