Stonefly

2022-04-27 • SymantecStonefly: North Korea-linked Spying Operation Con…

Stonefly is Symantec’s designation for a North Korea-linked cyberespionage group also known as Andariel, BlackMine, Silent Chollima, and Operation Troy. Symantec reported in April 2022 that the group had operated since at least 2009 and was linked to the Reconnaissance General Bureau. Stonefly focuses on intelligence collection from high-value targets and has attacked government, military, defense, aerospace, telecommunications, energy, finance, and advanced-technology organizations. Its operators exploit public-facing servers, deploy web shells, harvest credentials, move laterally with legitimate administration tools, and use custom backdoors including Preft, NukeSped, and TigerRAT. The group has also conducted financially motivated intrusions, including attacks on banks and cryptocurrency exchanges, while maintaining a strong espionage mission. Stonefly campaigns show patient network exploration, targeted collection, custom malware deployment, and abuse of trusted tools to sustain access inside strategically valuable organizations.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports in This Cluster

Top Authors

View Stonefly reports only

View Stonefly reports only