G0138

G0138Andariel

Description

[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. [Andariel](https://attack.mitre.org/groups/G0138)'s notable activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle.(Citation: FSI Andariel Campaign Rifle July 2017)(Citation: IssueMakersLab Andariel GoldenAxe May 2017)(Citation: AhnLab Andariel Subgroup of Lazarus June 2018)(Citation: TrendMicro New Andariel Tactics July 2018)(Citation: CrowdStrike Silent Chollima Adversary September 2021) [Andariel](https://attack.mitre.org/groups/G0138) is considered a sub-set of [Lazarus Group](https://attack.mitre.org/groups/G0032), and has been attributed to North Korea's Reconnaissance General Bureau.(Citation: Treasury North Korean Cyber Groups September 2019) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.

References

  1. https://attack.mitre.org/groups/G0138
  2. http://download.ahnlab.com/global/brochure/%5BAnalysis%5DAndariel_Group.pdf
  3. https://www.trendmicro.com/en_us/research/18/g/new-andariel-reconnaissance-tactics-hint-at-next-targets.html
  4. https://adversary.crowdstrike.com/en-US/adversary/silent-chollima/
  5. https://www.fsec.or.kr/user/bbs/fsec/163/344/bbsDataView/1680.do
  6. http://www.issuemakerslab.com/research3/
  7. https://home.treasury.gov/news/press-releases/sm774

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT37
Actor
Silent Chollima
Group
APT38
Group
Lazarus Group
Group
Higaisa
Software
holyghost
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.