← Back to Actors
Andariel
AndarielSilent ChollimaPLUTONIUMOnyx Sleet
[Andariel](https://attack.mitre.org/groups/G0138) is a North Korean state-sponsored threat group that has been active since at least 2009. [Andariel](https://attack.mitre.org/groups/G0138) has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a variety of domestic companies; they have also conducted cyber financial operations against ATMs, banks, and cryptocurrency exchanges. [Andariel](https://attack.mitre.org/groups/G0138)'s notable activity includes Operation Black Mine, Operation GoldenAxe, and C...
12
Techniques
12
Covered
0
Gaps
100%
Coverage
Coverage12/12
COVERED (12)
T1005Data from Local System51 det.T1027.003Steganography5 det.T1049System Network Connections Discovery23 det.T1057Process Discovery23 det.T1105Ingress Tool Transfer191 det.T1189Drive-by Compromise12 det.T1203Exploitation for Client Execution80 det.T1204.002Malicious File461 det.T1566.001Spearphishing Attachment1055 det.T1588.001Malware2 det.T1590.005IP Addresses4 det.T1592.002Software1 det.