Threat Advisory

North Korean Andariel APT Group Targets Military and Nuclear Programs

Threat: Malicious Campaign
Threat Actor Name: Andariel
Threat Actor Type: State-Sponsored
Targeted Region: U.S., South Korea, Japan & India
Alias: G0138, Silent Chollima, UNC577/UNC2970/UNC4131/UNC4369/TEMP.Hermit, Plutonium/Onyx Sleet, Stonefly, Nickel Hyatt, Andariel
Threat Actor Region: North Korea
Targeted Sector: Government & Defense, Healthcare, Aerospace & Aviation, Energy & Utilities, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

It highlights ongoing cyber espionage activities associated with the DPRK and RGB’s 3rd Bureau, specifically targeting defense, aerospace, nuclear, and engineering entities. This group, known as Andariel also referred to as Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa, aims to obtain sensitive information to advance DPRK’s military and nuclear programs. Entities in various countries, including Japan and India, remain at risk from this threat. Andariel funds its espionage through ransomware attacks on U.S. healthcare entities.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

It highlights ongoing cyber espionage activities associated with the DPRK and RGB’s 3rd Bureau, specifically targeting defense, aerospace, nuclear, and engineering entities. This group, known as Andariel also referred to as Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa, aims to obtain sensitive information to advance DPRK’s military and nuclear programs. Entities in various countries, including Japan and India, remain at risk from this threat. Andariel funds its espionage through ransomware attacks on U.S. healthcare entities.[emaillocker id="1283"]

 

The RGB 3rd Bureau actors finance their espionage through ransomware operations against U.S. healthcare entities. They exploit known vulnerabilities, such as Log4j, to gain initial access via web servers, deploying web shells and gaining access to sensitive information. They use standard system discovery and enumeration techniques, persistence mechanisms like Scheduled Tasks, and credential-stealing tools such as Mimikatz for privilege escalation. The actors deploy custom malware implants, remote access tools (RATs), and open-source tools for execution, lateral movement, and data exfiltration. Additionally, they conduct phishing campaigns using malicious attachments, including Microsoft Windows Shortcut File (LNK) and HTML Application (HTA) script files. The group employs a variety of reconnaissance techniques and leverages CVEs like CVE-2023-46604, CVE-2023-3519, and CVE-2023-27997. They utilize both custom and commodity malware, including RATs like MagicRAT, Valefor, and NukeSped, for remote access, data manipulation, and command and control (C2) operations.

 

To counter these threats, organizations, especially in critical infrastructure, should apply timely patches for vulnerabilities, protect web servers from web shells, monitor endpoints for malicious activity, and strengthen authentication and remote access protections. By implementing these mitigations, organizations can enhance their cybersecurity posture against ongoing cyber espionage activities by the DPRK's RGB 3rd Bureau.

THREAT PROFILE:

Tactic Technique Id Technique
Reconnaissance T1591 Gather Victim Org Information
 T1592 Gather Victim Host Information
 T1595 Active Scanning
T1596 Search Open Technical Databases
Resource Development T1587 Develop Capabilities
Initial Access T1190 Exploit Public-Facing Application
 Execution T1059 Command and Scripting Interpreter
 Defense Evasion T1027 Obfuscated Files or Information
Credential Access T1003 OS Credential Dumping
 Discovery T1083 File and Directory Discovery
T1087 Account Discovery
Lateral Movement T1021 Remote Services
Collection T1560 Archive Collected Data
T1039 Data from Network Shared Drive
Command and Control  T1572 Protocol Tunneling
T1071 Application Layer Protocol
 T1090 Proxy
Exfiltration T1048 Exfiltration Over Alternative Protocol
T1567 Exfiltration Over Web Service

REFERENCES:

The following reports contain further technical details:
https://www.cisa.gov/sites/default/files/2024-07/aa24-207a-dprk-cyber-group-conducts-global-espionage-campaign.pdf

[/emaillocker]
crossmenu