Andariel has collected large numbers of files from compromised network systems for later extraction.7
group
Andariel G0138
- Created
- 29 September 2021
- Last modified
- 31 July 2026
- Aliases
- Andariel · Silent Chollima · PLUTONIUM · Onyx Sleet
Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. Andariel's notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.[1][2][3][4][5]
Andariel is considered a sub-set of Lazarus Group, and has been attributed to North Korea's Reconnaissance General Bureau.[6]
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0138
Andariel has hidden malicious executables within PNG files.89
Andariel has used the netstat -naop tcp command to display TCP connections on a victim's machine.10
Andariel has used tasklist to enumerate processes and find a specific string.11
Andariel has downloaded additional tools and malware onto compromised hosts.12
Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.1314
Standing G0138
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
39th percentile · 61% of 176 ATT&CK groups have more Enterprise techniques.
48th percentile · 52% of 176 ATT&CK groups have more tactics spanned.
39th percentile · 61% of 176 ATT&CK groups have more tools and malware.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
40th percentile · 60% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0138
350 distinct rules cover the 12 techniques recorded for this group. The 365 technique-to-rule mappings resolve to 350 distinct rules, because one rule can cover several techniques. 217 Sigma · 133 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org