Description
Andariel is a sub-group of the North Korean Lazarus threat actor cluster that focuses on financial theft and espionage against South Korean and international organizations. Its operations have included ransomware deployments and attacks that harvest funds from ATM systems and cryptocurrency businesses.
Stats
- First seen
- June 2024
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Andariel |
| Gen:Variant.Andariel.1 |
| Gen:Variant.Andariel.2 |
| Gen:Variant.Andariel.4 |
| Gen:Variant.Andariel.5 |
| Gen:Variant.Andariel.6 |
| Gen:Variant.Andariel.7 |
| Gen:Variant.Andariel.9 |
| Trojan.Andariel.1 |
| Trojan.Andariel.10 |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Win.Trojan.Andariel outbound connection |