Initial Access
2 techniques·derived
Log4Shell, Apache ActiveMQ, and TeamCity exploitation.
Steals defence and nuclear technology, then funds the operation with ransomware against hospitals. An indicted RGB officer remains at large.
ATTRIBUTED TONorth Korea › RGB — Reconnaissance General Bureau, 3rd Bureau › 3rd Bureau (Andariel / Onyx Sleet)
Andariel operates under the Reconnaissance General Bureau's 3rd Bureau and runs an unusual dual mission: military and nuclear technology collection, financed in part by ransomware against civilian targets.
A July 2024 joint advisory from the U.S., U.K., and South Korea documented the group targeting defence contractors, nuclear facilities, aerospace firms, and engineering companies across multiple countries to obtain classified military and nuclear technical data — tank designs, submarine and naval vessel specifications, uranium processing information, and missile technology.
The same advisory documented how the group pays for that work. Andariel deploys ransomware — including the Maui family — against U.S. healthcare organisations and other civilian targets, using the proceeds to fund continued espionage. A May 2021 attack on a Kansas hospital, in which the ransom was paid and later partially recovered by the FBI, was directly cited in the indictment.
That indictment, unsealed in July 2024, charged Rim Jong Hyok, identified as an RGB 3rd Bureau member operating through the Pyongyang University of Automation and front organisations. The State Department offered a reward of up to $10 million. He remains at large.
The group has also compromised South Korean defence contractors and, in 2022, was linked to the theft of technical data from organisations supporting the Korean defence industrial base.
Down to the named unit where public evidence supports it.
Rim Jong Hyok was indicted by the U.S. Department of Justice in July 2024, identified as a member of the RGB's 3rd Bureau operating through front organisations including the Pyongyang University of Automation. The indictment covers ransomware attacks on U.S. healthcare providers and espionage against defence and nuclear targets. The U.S. Treasury sanctioned Andariel in September 2019 as an RGB-controlled entity alongside Lazarus and Bluenoroff.
Attributing sources
10 designators across 9 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Manually operated ransomware used against U.S. healthcare organisations to fund espionage operations.
Malpedia ↗Modular backdoor for reconnaissance and data theft in defence and industrial environments.
Malpedia ↗Implant supporting keylogging, screen capture, and port forwarding, used against South Korean targets.
Lightweight Go-based implant used in more recent defence-sector intrusions.
Backdoor family shared with other DPRK clusters, used for durable network access.
Shared, commodity & living-off-the-land
Native Windows tooling used extensively in place of custom malware during lateral movement.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Andariel | ||
|---|---|---|---|---|
| CVE-2023-42793KEVransomware | 9.8 | JetBrains TeamCityJetBrains | 1 Oct 2023 | TeamCity RCE exploited for access to build systems and source repositories at software organisations.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 1 Jan 2022 | Log4Shell exploited against internet-facing services at defence and energy targets for initial access.SRCFBI / CISA and partners ↗ |
| CVE-2019-0708KEVransomware | 9.8 | Windows RDPMicrosoft | 1 Jan 2021 | BlueKeep RDP vulnerability scanned for and exploited against exposed systems at targeted organisations.SRCFBI / CISA and partners ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
2 techniques·derived
Log4Shell, Apache ActiveMQ, and TeamCity exploitation.
1 technique·derived
Code Signing.
1 technique·derived
LSASS Memory.
1 technique·derived
Remote Desktop Protocol.
2 techniques·derived
Defence engineering repositories and technical documentation.
1 technique·derived
Web Protocols.
2 techniques·derived
Maui ransomware against healthcare providers to fund espionage. Ransom payments laundered through Chinese-based facilitators.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Log4Shell, Apache ActiveMQ, and TeamCity exploitation
Defence engineering repositories and technical documentation
Maui ransomware against healthcare providers to fund espionage
Ransom payments laundered through Chinese-based facilitators
Ransomware deployed against U.S. hospitals and healthcare providers, with the proceeds funding continued espionage against defence and nuclear targets. A May 2021 attack on a Kansas hospital was cited directly in the July 2024 indictment of RGB officer Rim Jong Hyok.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both RGB elements, sanctioned together by the U.S. Treasury in September 2019.
Both RGB financial-capable elements with distinct primary missions.
Both under the RGB umbrella with complementary collection requirements.
Curated links to the reports that established what is known about this group.