ATT&CKReferencesAhnLab Andariel Subgroup of Lazarus June 2018

AhnLab Andariel Subgroup of Lazarus June 2018

AhnLab. (2018, June 23). Targeted attacks by Andariel Threat Group, a subgroup of the Lazarus. Retrieved September 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1105
Ingress Tool Transfer
GroupAndariel

Andariel has downloaded additional tools and malware onto compromised hosts.

T1189
Drive-by Compromise
GroupAndariel

Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.

T1204.002
Malicious File
GroupAndariel

Andariel has attempted to lure victims into enabling malicious macros within email attachments.

T1566.001
Spearphishing Attachment
GroupAndariel

Andariel has conducted spearphishing campaigns that included malicious Word or Excel attachments.

T1590.005
IP Addresses
GroupAndariel

Andariel has limited its watering hole attacks to specific IP address ranges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.