Netskope Threat Labs

Andariel

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Andariel is a sub-group of the North Korean Lazarus threat actor cluster that focuses on financial theft and espionage against South Korean and international organizations. Its operations have included ransomware deployments and attacks that harvest funds from ATM systems and cryptocurrency businesses.

First seen
June 2024
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.Andariel
Gen:Variant.Andariel.1
Gen:Variant.Andariel.2
Gen:Variant.Andariel.4
Gen:Variant.Andariel.5
Gen:Variant.Andariel.6
Gen:Variant.Andariel.7
Gen:Variant.Andariel.9
Trojan.Andariel.1
Trojan.Andariel.10