the Maiden of Anguish
First seen: 2017-07 •
Last seen: 2026-05
#AnOctopus • 2024-06
Andariel targeted centralized management solutions used by South Korean enterprises, abusing exposed administrator console ports, vulnerable management software, and later supply-chain distribution paths through developers with downstream customers. Linked evidence describes retained attacker account activity, Golang-based malicious code, protected virtual images, leased Korean hosting infrastructure, remote-control malware tooling, and interest in Korean DLP and antivirus software code.
3
Related Reports
1
Affected Countries
24
Months Since
the Maiden of Anguish