Andariel
MITREUnknown
Unknown
Unknown
[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. [Andariel](https://attack.mitre.org/groups/G0138)'s notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021)
[Andariel](https://attack.mitre.org/groups/G0138) is considered a sub-set of [Lazarus Group](https://attack.mitre.org/groups/G0032), and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019)
North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.
Tecniche Utilizzate (12)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1005 | Data from Local System | - |
| T1027.003 | Steganography | - |
| T1049 | System Network Connections Discovery | - |
| T1057 | Process Discovery | - |
| T1105 | Ingress Tool Transfer | - |
| T1189 | Drive-by Compromise | - |
| T1203 | Exploitation for Client Execution | - |
| T1204.002 | Malicious File | - |
| T1566.001 | Spearphishing Attachment | - |
| T1588.001 | Malware | - |
| T1590.005 | IP Addresses | - |
| T1592.002 | Software | - |
Alias (312)
Malware Utilizzato (2)
Metadata
| ID: | 888 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |