{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "andariel",
    "slug": "andariel",
    "name": "Andariel",
    "shortName": "Andariel",
    "country": "North Korea",
    "countryCode": "KP",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2015",
    "prominence": 77,
    "mitreGroupId": "G0138",
    "malpediaSlug": "andariel",
    "tagline": "Steals defence and nuclear technology, then funds the operation with ransomware against hospitals. An indicted RGB officer remains at large.",
    "bio": "Andariel operates under the Reconnaissance General Bureau's 3rd Bureau and runs an unusual dual mission: military and nuclear technology collection, financed in part by ransomware against civilian targets.\n\nA July 2024 joint advisory from the U.S., U.K., and South Korea documented the group targeting defence contractors, nuclear facilities, aerospace firms, and engineering companies across multiple countries to obtain classified military and nuclear technical data — tank designs, submarine and naval vessel specifications, uranium processing information, and missile technology.\n\nThe same advisory documented how the group pays for that work. Andariel deploys ransomware — including the Maui family — against U.S. healthcare organisations and other civilian targets, using the proceeds to fund continued espionage. A May 2021 attack on a Kansas hospital, in which the ransom was paid and later partially recovered by the FBI, was directly cited in the indictment.\n\nThat indictment, unsealed in July 2024, charged Rim Jong Hyok, identified as an RGB 3rd Bureau member operating through the Pyongyang University of Automation and front organisations. The State Department offered a reward of up to $10 million. He remains at large.\n\nThe group has also compromised South Korean defence contractors and, in 2022, was linked to the theft of technical data from organisations supporting the Korean defence industrial base.",
    "attribution": {
      "sponsor": "North Korea",
      "service": "RGB — Reconnaissance General Bureau, 3rd Bureau",
      "unit": "3rd Bureau (Andariel / Onyx Sleet)",
      "confidence": "confirmed",
      "summary": "Rim Jong Hyok was indicted by the U.S. Department of Justice in July 2024, identified as a member of the RGB's 3rd Bureau operating through front organisations including the Pyongyang University of Automation. The indictment covers ransomware attacks on U.S. healthcare providers and espionage against defence and nuclear targets. The U.S. Treasury sanctioned Andariel in September 2019 as an RGB-controlled entity alongside Lazarus and Bluenoroff.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "North Korean Government Hacker Charged for Involvement in Ransomware Attacks Targeting US Hospitals and Health Care Providers",
          "url": "https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals",
          "date": "2024-07-25"
        },
        {
          "org": "FBI / CISA / NSA / NCSC-UK / ROK NIS",
          "title": "North Korea State-Sponsored Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs (AA24-207A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a",
          "date": "2024-07-25"
        }
      ]
    },
    "motivations": [
      "espionage",
      "financial-gain",
      "ip-theft"
    ],
    "targetSectors": [
      "Defense",
      "Nuclear",
      "Aerospace",
      "Healthcare",
      "Manufacturing",
      "Energy",
      "Government",
      "Technology",
      "Education"
    ],
    "targetCountries": [
      "United States",
      "South Korea",
      "Japan",
      "United Kingdom",
      "India",
      "Taiwan"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Andariel",
        "url": "https://attack.mitre.org/groups/G0138/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Onyx Sleet",
        "correlation": "exact",
        "note": "Formerly PLUTONIUM"
      },
      {
        "org": "microsoft",
        "name": "PLUTONIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Silent Chollima",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT45",
        "correlation": "exact",
        "note": "Mandiant graduated the cluster to APT45 in July 2024"
      },
      {
        "org": "secureworks",
        "name": "NICKEL HYATT",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "Andariel",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Andariel / Stonefly",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Stonefly",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Jumpy Pisces",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Maui ransomware",
        "type": "ransomware",
        "custom": true,
        "description": "Manually operated ransomware used against U.S. healthcare organisations to fund espionage operations.",
        "malpediaSlug": "win.maui_ransomware"
      },
      {
        "name": "SHATTEREDGLASS / Dtrack",
        "type": "backdoor",
        "custom": true,
        "description": "Modular backdoor for reconnaissance and data theft in defence and industrial environments.",
        "malpediaSlug": "win.dtrack"
      },
      {
        "name": "TigerRAT",
        "type": "backdoor",
        "custom": true,
        "description": "Implant supporting keylogging, screen capture, and port forwarding, used against South Korean targets."
      },
      {
        "name": "Preft / Dora RAT",
        "type": "backdoor",
        "custom": true,
        "description": "Lightweight Go-based implant used in more recent defence-sector intrusions."
      },
      {
        "name": "Living-off-the-land utilities",
        "type": "lotl",
        "custom": false,
        "description": "Native Windows tooling used extensively in place of custom malware during lateral movement."
      },
      {
        "name": "Nukesped",
        "type": "backdoor",
        "custom": true,
        "description": "Backdoor family shared with other DPRK clusters, used for durable network access."
      }
    ],
    "techniques": [
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Log4Shell, Apache ActiveMQ, and TeamCity exploitation"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1486",
        "name": "Data Encrypted for Impact",
        "tactic": "Impact",
        "note": "Maui ransomware against healthcare providers to fund espionage"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact",
        "note": "Ransom payments laundered through Chinese-based facilitators"
      },
      {
        "tCode": "T1213",
        "name": "Data from Information Repositories",
        "tactic": "Collection",
        "note": "Defence engineering repositories and technical documentation"
      },
      {
        "tCode": "T1003.001",
        "name": "OS Credential Dumping: LSASS Memory",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1021.001",
        "name": "Remote Services: Remote Desktop Protocol",
        "tactic": "Lateral Movement"
      },
      {
        "tCode": "T1560",
        "name": "Archive Collected Data",
        "tactic": "Collection"
      },
      {
        "tCode": "T1071.001",
        "name": "Application Layer Protocol: Web Protocols",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1553.002",
        "name": "Subvert Trust Controls: Code Signing",
        "tactic": "Defense Evasion"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2021-44228",
        "firstExploited": "2022-01-01",
        "usage": "Log4Shell exploited against internet-facing services at defence and energy targets for initial access.",
        "source": {
          "org": "FBI / CISA and partners",
          "title": "AA24-207A: North Korea State-Sponsored Cyber Group Conducts Global Espionage Campaign",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a",
          "date": "2024-07-25"
        }
      },
      {
        "cveId": "CVE-2023-42793",
        "firstExploited": "2023-10-01",
        "usage": "TeamCity RCE exploited for access to build systems and source repositories at software organisations.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Multiple North Korean threat actors exploiting the TeamCity vulnerability",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/",
          "date": "2023-10-18"
        }
      },
      {
        "cveId": "CVE-2019-0708",
        "firstExploited": "2021-01-01",
        "usage": "BlueKeep RDP vulnerability scanned for and exploited against exposed systems at targeted organisations.",
        "source": {
          "org": "FBI / CISA and partners",
          "title": "AA24-207A: North Korea State-Sponsored Cyber Group Conducts Global Espionage Campaign",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a",
          "date": "2024-07-25"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "lazarus",
        "type": "same-sponsor",
        "confidence": "confirmed",
        "note": "Both RGB elements, sanctioned together by the U.S. Treasury in September 2019."
      },
      {
        "relatedActorId": "apt38",
        "type": "same-sponsor",
        "confidence": "confirmed",
        "note": "Both RGB financial-capable elements with distinct primary missions."
      },
      {
        "relatedActorId": "kimsuky",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both under the RGB umbrella with complementary collection requirements."
      }
    ],
    "reports": [
      {
        "org": "FBI / CISA / NSA and partners",
        "title": "AA24-207A: North Korea State-Sponsored Cyber Group Conducts Global Espionage Campaign",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a",
        "date": "2024-07-25"
      },
      {
        "org": "U.S. Department of Justice",
        "title": "Indictment: US v. Rim Jong Hyok (RGB 3rd Bureau)",
        "url": "https://www.justice.gov/opa/media/1361896/dl",
        "date": "2024-07-25"
      },
      {
        "org": "CISA / FBI / Treasury",
        "title": "AA22-187A: North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target Healthcare",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a",
        "date": "2022-07-06"
      },
      {
        "org": "Symantec",
        "title": "Stonefly: North Korea-linked Group Continues to Target U.S. Firms",
        "url": "https://symantec-enterprise-blogs.security.com/threat-intelligence/stonefly-north-korea-attacks",
        "date": "2024-10-03"
      }
    ],
    "campaigns": [
      {
        "id": "andariel-maui",
        "actorId": "andariel",
        "name": "Maui Ransomware Against U.S. Healthcare",
        "date": "2021-05-01",
        "endDate": "2023-04-01",
        "significance": "major",
        "targetSectors": [
          "Healthcare",
          "Defense",
          "Nuclear"
        ],
        "targetCountries": [
          "United States",
          "South Korea"
        ],
        "cveIds": [
          "CVE-2021-44228"
        ],
        "summary": "Ransomware deployed against U.S. hospitals and healthcare providers, with the proceeds funding continued espionage against defence and nuclear targets. A May 2021 attack on a Kansas hospital was cited directly in the July 2024 indictment of RGB officer Rim Jong Hyok.",
        "sources": [
          {
            "org": "CISA / FBI / Treasury",
            "title": "AA22-187A: North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target Healthcare",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a",
            "date": "2022-07-06"
          },
          {
            "org": "U.S. Department of Justice",
            "title": "North Korean Government Hacker Charged in Ransomware Attacks on U.S. Hospitals",
            "url": "https://www.justice.gov/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals",
            "date": "2024-07-25"
          }
        ]
      }
    ],
    "flag": "🇰🇵",
    "profile": "/apt/andariel/"
  }
}