Skip to content
North KoreaState-SponsoredActiveMITRE G0138Malpedia ↗

Andariel

Steals defence and nuclear technology, then funds the operation with ransomware against hospitals. An indicted RGB officer remains at large.

ATTRIBUTED TONorth Korea › RGB — Reconnaissance General Bureau, 3rd Bureau › 3rd Bureau (Andariel / Onyx Sleet)

Open MITRE Navigator layer ↗Download profile JSON
Active
2015–present
Motivation
Espionage, Financial Gain, IP Theft
Aliases
10
Exploited CVEs
3
ATT&CK techniques
10
Cited sources
9

Overview

Andariel operates under the Reconnaissance General Bureau's 3rd Bureau and runs an unusual dual mission: military and nuclear technology collection, financed in part by ransomware against civilian targets.

A July 2024 joint advisory from the U.S., U.K., and South Korea documented the group targeting defence contractors, nuclear facilities, aerospace firms, and engineering companies across multiple countries to obtain classified military and nuclear technical data — tank designs, submarine and naval vessel specifications, uranium processing information, and missile technology.

The same advisory documented how the group pays for that work. Andariel deploys ransomware — including the Maui family — against U.S. healthcare organisations and other civilian targets, using the proceeds to fund continued espionage. A May 2021 attack on a Kansas hospital, in which the ransom was paid and later partially recovered by the FBI, was directly cited in the indictment.

That indictment, unsealed in July 2024, charged Rim Jong Hyok, identified as an RGB 3rd Bureau member operating through the Pyongyang University of Automation and front organisations. The State Department offered a reward of up to $10 million. He remains at large.

The group has also compromised South Korean defence contractors and, in 2022, was linked to the theft of technical data from organisations supporting the Korean defence industrial base.

Attribution

Down to the named unit where public evidence supports it.

North KoreaRGB — Reconnaissance General Bureau, 3rd Bureau3rd Bureau (Andariel / Onyx Sleet)Confirmed

Rim Jong Hyok was indicted by the U.S. Department of Justice in July 2024, identified as a member of the RGB's 3rd Bureau operating through front organisations including the Pyongyang University of Automation. The indictment covers ransomware attacks on U.S. healthcare providers and espionage against defence and nuclear targets. The U.S. Treasury sanctioned Andariel in September 2019 as an RGB-controlled entity alongside Lazarus and Bluenoroff.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 9 organisations.

MITRE ATT&CK

index ↗
  • Andariel

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Onyx SleetFormerly PLUTONIUM
  • PLUTONIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Silent Chollima

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT45Mandiant graduated the cluster to APT45 in July 2024

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • NICKEL HYATT

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Jumpy Pisces

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Kaspersky GReAT

index ↗
  • Andariel

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Symantec (Broadcom)

index ↗
  • Stonefly

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • Andariel / Stonefly

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesSouth KoreaJapanUnited KingdomIndiaTaiwan

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Maui ransomwareransomware

Manually operated ransomware used against U.S. healthcare organisations to fund espionage operations.

Malpedia ↗
SHATTEREDGLASS / Dtrackbackdoor

Modular backdoor for reconnaissance and data theft in defence and industrial environments.

Malpedia ↗
TigerRATbackdoor

Implant supporting keylogging, screen capture, and port forwarding, used against South Korean targets.

Preft / Dora RATbackdoor

Lightweight Go-based implant used in more recent defence-sector intrusions.

Nukespedbackdoor

Backdoor family shared with other DPRK clusters, used for durable network access.

Shared, commodity & living-off-the-land

Living-off-the-land utilitieslotl

Native Windows tooling used extensively in place of custom malware during lateral movement.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Andariel
CVE-2023-42793KEVransomware9.81 Oct 2023TeamCity RCE exploited for access to build systems and source repositories at software organisations.SRCMicrosoft Threat Intelligence
CVE-2021-44228KEVransomware10.01 Jan 2022Log4Shell exploited against internet-facing services at defence and energy targets for initial access.SRCFBI / CISA and partners
CVE-2019-0708KEVransomware9.81 Jan 2021BlueKeep RDP vulnerability scanned for and exploited against exposed systems at targeted organisations.SRCFBI / CISA and partners

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 7 tactics · 4 with actor-specific notes

Initial Access

2

Collection

2

Impact

2

Campaign timeline

  1. Maui Ransomware Against U.S. Healthcare

    Ransomware deployed against U.S. hospitals and healthcare providers, with the proceeds funding continued espionage against defence and nuclear targets. A May 2021 attack on a Kansas hospital was cited directly in the July 2024 indictment of RGB officer Rim Jong Hyok.

    CVE-2021-44228HealthcareDefenseNuclear

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.