Activity timeline
Andariel appears in 25 tracked threats between and ; the busiest month was 2026-07 with 6 reports.
ATT&CK techniques observed
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 19 of 25 tracked threats
- T1005 Data from Local System — Collectionobserved in 18 of 25 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 18 of 25 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 18 of 25 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 16 of 25 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 14 of 25 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 13 of 25 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 11 of 25 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 11 of 25 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 11 of 25 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 11 of 25 tracked threats
- T1657 Financial Theft — Impactobserved in 11 of 25 tracked threats
- T1204 User Execution — Executionobserved in 10 of 25 tracked threats
- T1113 Screen Capture — Collectionobserved in 9 of 25 tracked threats
- T1555 Credentials from Password Stores — Credential Accessobserved in 9 of 25 tracked threats
Tracked threats
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow AbuseCRITICAL
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2HIGH
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense IndustryCRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)CRITICAL
- North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean Targets ("Operation Double Barrel")HIGH
- State-Sponsored Actors Exploit AnySign4PC Zero-Day via Compromised Watering-Hole Sites to Deploy SIGNBT and COPPERHEDGE BackdoorsCRITICAL
- NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoYMEDIUM
- PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret)HIGH
- Lazarus-Linked npm Malware Masquerades as Rollup Polyfills (rollup-packages-polyfill-core, rollup-runtime-polyfill-core, swift-parse-stream, quirky-token, rollup-plugin-polyfill-connect, react-icon-svgs)HIGH
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion TechniquesHIGH
- Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)HIGH
- Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)HIGH
- RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage ChainHIGH
- Lazarus RemotePE Memory-Only RAT — DPAPILoader + RemotePELoader Chain Targeting Financial & Cryptocurrency FirmsHIGH
- Lazarus Group (DPRK) Hides BeaverTail / InvisibleFerret Loader in Git Hooks via precommit.vercel.app — Contagious Interview / TaskJacker Evolution (May 2026)HIGH
- KelpDAO LayerZero Bridge Exploit — $292M rsETH Minted Against Non-Existent Burn (Lazarus Group, April 2026)CRITICAL
- Apache ActiveMQ OpenWire Deserialization RCE (CVE-2023-46604) — 6,400 Brokers Actively Exploited by HelloKitty, Kinsing, TellYouThePass and Andariel (Lazarus)CRITICAL
- DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package PoisoningHIGH
- Supply Chain Attacks on Crypto Ecosystem via Developer Toolchain CompromiseHIGH
- Lazarus Group (Stonefly) Medusa Ransomware — DPRK State-Backed Actors Deploy Medusa RaaS Targeting U.S. HealthcareCRITICAL
- Contagious Interview IDE Task Hijacking — North Korean BeaverTail/PyLangGhost/GolangGhost via VS Code & Cursor Tasks, GitHub Gist Staging, Developer TargetingHIGH
- Lazarus Group Medusa Ransomware — North Korean State-Backed Extortion Targeting US Healthcare and Middle EastCRITICAL
- Matryoshka ClickFix macOS Variant — Nested Heredoc Obfuscation, AppleScript Credential Stealer, Trezor Suite Replacement, Ledger Live Surgical Patching, API-Gated C2HIGH
- LABYRINTH CHOLLIMA Evolves into Three DPRK AdversariesCRITICAL
Related CVEs
- CVE-2026-72971
- CVE-2026-70332
- CVE-2026-70130
- CVE-2026-68823
- CVE-2026-68820
- CVE-2026-68816
- CVE-2026-68804
- CVE-2026-68794
- CVE-2026-65813
- CVE-2026-65789
- CVE-2026-65665
- CVE-2026-65657
- CVE-2026-64921
- CVE-2026-64911
- CVE-2026-64910
- CVE-2026-64909
- CVE-2026-64907
- CVE-2026-64903
- CVE-2026-64898
- CVE-2026-63532
- CVE-2026-63526
- CVE-2026-63525
- CVE-2026-63520
- CVE-2026-63518
- CVE-2026-63515
- CVE-2026-62915
- CVE-2026-62914
- CVE-2026-62913
- CVE-2026-62912
- CVE-2026-62911
- CVE-2026-62910
- CVE-2026-62893
- CVE-2026-62890
- CVE-2026-62889
- CVE-2026-62878
- CVE-2026-62869
- CVE-2026-62832
- CVE-2026-62827
- CVE-2026-62824
- CVE-2026-62823