Andariel
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Andariel, also tracked as APT‑C‑26, is a threat actor publicly associated with North Korea and frequently linked to the broader Lazarus APT umbrella. The group operates under these aliases in open‑source reporting and is identified as a state‑nexious entity originating from the Democratic People’s Republic of Korea. Its activities are attributed to North Korean state interests based on the technical overlap with known Lazarus infrastructure and the geopolitical context of its targets.
The actor’s known operations focus on South Korean government and defense‑related organizations, as illustrated by a 2017 incident in which a South Korean national security think tank was compromised. In that campaign the group sought to gather intelligence by profiling visitors’ browser and operating system configurations, indicating an espionage‑oriented objective. The same operation referenced command‑and‑control servers that had been used in earlier Lazarus financial heists, showing a historical connection to financially motivated activity alongside its intelligence‑gathering goals.
Andariel’s typical tactics include exploiting zero‑day vulnerabilities in ActiveX controls to gain initial access through compromised websites, delivering malicious ActiveX controls that execute reconnaissance scripts. These scripts collect system information before deploying the Akdoor backdoor, which allows the actor to issue commands via the Windows Command Prompt. The group’s tooling style relies on reusing previously associated domains and filenames tied to past Lazarus campaigns, demonstrating a consistent infrastructure reuse pattern.
The 2017 ActiveX zero‑day attack on the South Korean think tank stands as a representative publicly reported operation, highlighting the actor’s use of web‑based exploits, profiling techniques, and backdoor deployment to achieve its objectives. This incident exemplifies Andariel’s blend of espionage‑focused reconnaissance and its linkage to broader Lazarus financial‑operation infrastructure.
Incidents
Attributed incidents are available to members.
1 incident