Andariel
2024-12-28 • screaminggoat •
This Andariel profile identifies the DPRK-linked group as Lab 110 / 3rd Bureau of the Reconnaissance General Bureau and catalogs its aliases, relationships, exploited vulnerabilities, and reporting history. The page maps Andariel to aliases such as APT45, Onyx Sleet, Silent Chollima, Stonefly, Jumpy Pisces, Nickel Hyatt, and TA430, and describes objectives spanning espionage and ransomware. It highlights exploitation of enterprise software vulnerabilities including JetBrains TeamCity CVE-2023-42793, Apache ActiveMQ CVE-2023-46604, Atlassian Confluence CVE-2023-22515, PaperCut CVE-2023-27350, and Log4Shell CVE-2021-44228. The referenced reporting connects Andariel to attacks against Korean companies, defense and critical sectors, TeamCity and ActiveMQ exploitation, ransomware activity including Maui/healthcare targeting, and malware families or tooling such as SmallTiger, Xctdoor, Dora RAT, DTrack, PEBBLEDASH, and NukeSped. The entry is best treated as an actor reference page rather than a single incident report.