Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

Andariel

Aliases: Silent Chollima, PLUTONIUM, Onyx Sleet, APT45, Stonefly • Andariel is a North Korean threat group known for destructive attacks against South Korea and cyber financial operations.
Profile
Malicious
Category
Threat Actor Group
Threat Type
KP
Country
andariel
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

Andariel is a North Korean state-sponsored threat group that has conducted destructive attacks against South Korean government and military organizations and engaged in cyber financial operations. Andariel is considered a subset of the Lazarus Group.

Aliases (5)
Silent Chollima
Alias
PLUTONIUM
Alias
Onyx Sleet
Alias
APT45
Alias
Stonefly
Alias
Targets (1)
South Korea (Government, Military)
Target
External Sources