G0138

2021-09-29 • MITREAndariel

MITRE ATT&CK documents G0138 as Andariel, a North Korean state-sponsored threat group active since at least 2009 and considered a subset of Lazarus Group, attributed to North Korea's Reconnaissance General Bureau. The group has primarily targeted South Korean government agencies, military organizations, and a variety of domestic companies, including destructive attacks, and has also conducted cyber-financial operations against ATMs, banks, and cryptocurrency exchanges; notable named activity includes Operation Black Mine, Operation GoldenAxe, and Campaign Rifle. Documented techniques include watering-hole attacks (often using zero-day exploits) limited to specific victim IP ranges, exploitation of ActiveX vulnerabilities, spearphishing with malicious Word or Excel attachments and macro lures, hiding executables inside PNG files via steganography, bulk collection of files from compromised systems, and use of publicly available remote access trojans including gh0st RAT and Rifdoor.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports in This Cluster

Top Authors

View G0138 reports only

View G0138 reports only