Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-02

Andariel

Also known as:Onyx SleetPLUTONIUMSilent ChollimaStoneflyLazarus subgroup

As of 2026-09-30, Andariel is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 25 threats spanning apt, supply chain, zero day. Also known as Onyx Sleet, PLUTONIUM, Silent Chollima, Stonefly. ATT&CK coverage spans 205 techniques across 15 tactics in 25 of 25 tracked threats. Most-observed techniques: T1041 (Exfiltration Over C2 Channel), T1005 (Data from Local System), T1082 (System Information Discovery).

Tracked threats
2510 critical · 14 high · 1 medium
First seen
2026-02-12
Last seen
2026-09-25
ATT&CK techniques
205across 25 of 25 threats
Related CVEs
63Referenced by its activity
Attribution
North KoreaNation or origin
Nation: North Korea · 25 tracked threat(s) · Categories: APT, SUPPLY_CHAIN, ZERO_DAY, VULNERABILITY, MALWARE, RANSOMWARE, PHISHING

Activity timeline

Andariel appears in 25 tracked threats between and ; the busiest month was 2026-07 with 6 reports.

ATT&CK techniques observed

205 techniques observed across 25 of 25 tracked threats · Stealth (formerly Defense Evasion) (43), Command and Control (20), Credential Access (19), Execution (18), Discovery (16), Resource Development (16)
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 19 of 25 tracked threats
  • T1005 Data from Local System — Collectionobserved in 18 of 25 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 18 of 25 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 18 of 25 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 16 of 25 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 14 of 25 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 13 of 25 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 11 of 25 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 11 of 25 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 11 of 25 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 11 of 25 tracked threats
  • T1657 Financial Theft — Impactobserved in 11 of 25 tracked threats
  • T1204 User Execution — Executionobserved in 10 of 25 tracked threats
  • T1113 Screen Capture — Collectionobserved in 9 of 25 tracked threats
  • T1555 Credentials from Password Stores — Credential Accessobserved in 9 of 25 tracked threats

Tracked threats

Related CVEs

40 of 63 CVEs referenced by tracked Andariel activity