CSIDB logo
Threat actor

Andariel

Attribution profile

Type
Nation State
Location
North Korea
Known incidents
1 incident
First seen
2017-01-01
Last seen
2017-01-01
Updated
2026-08-01 08:05
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Andariel, also tracked as APT‑C‑26, is a threat actor publicly associated with North Korea and frequently linked to the broader Lazarus APT umbrella. The group operates under these aliases in open‑source reporting and is identified as a state‑nexi­ous entity originating from the Democratic People’s Republic of Korea. Its activities are attributed to North Korean state interests based on the technical overlap with known Lazarus infrastructure and the geopolitical context of its targets.

The actor’s known operations focus on South Korean government and defense‑related organizations, as illustrated by a 2017 incident in which a South Korean national security think tank was compromised. In that campaign the group sought to gather intelligence by profiling visitors’ browser and operating system configurations, indicating an espionage‑oriented objective. The same operation referenced command‑and‑control servers that had been used in earlier Lazarus financial heists, showing a historical connection to financially motivated activity alongside its intelligence‑gathering goals.

Andariel’s typical tactics include exploiting zero‑day vulnerabilities in ActiveX controls to gain initial access through compromised websites, delivering malicious ActiveX controls that execute reconnaissance scripts. These scripts collect system information before deploying the Akdoor backdoor, which allows the actor to issue commands via the Windows Command Prompt. The group’s tooling style relies on reusing previously associated domains and filenames tied to past Lazarus campaigns, demonstrating a consistent infrastructure reuse pattern.

The 2017 ActiveX zero‑day attack on the South Korean think tank stands as a representative publicly reported operation, highlighting the actor’s use of web‑based exploits, profiling techniques, and backdoor deployment to achieve its objectives. This incident exemplifies Andariel’s blend of espionage‑focused reconnaissance and its linkage to broader Lazarus financial‑operation infrastructure.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB