North Korean hackers Andariel , who were primarily known for cyberespionage operations , have now expanded into financially motivated attacks , which include the development of ransomware .

Mandiant is tracking the group under the name APT45, although it is also known as Andariel, Nickel Hyatt, Onyx Sleet, Stonefly, and Silent Chollima.
According to researchers Taylor Long, Jeff Johnson, Alice Revelli, Fred Plan, and Michael Barnhart, APT45 has been conducting espionage since 2009 and primarily targets organizations that belong to critical infrastructure.
See also: RA World ransomware group attacks the construction sector
APT45 (like APT38-BlueNoroff, APT43-Kimsuky, and Lazarus Group), belongs to Reconnaissance General Bureau (RGB), which is the country's top military intelligence organization.
North Korean hackers Andariel – APT45 have also been linked to the development of ransomware (SHATTEREDGLASS and Maui) in attacks targeting South Korea, Japan and the US.
“It is likely that APT45 is committing cybercrime with financial motives, not only to support its own operations, but to generate funds for other North Korean state priorities,” Mandiant said.
See also: Los Angeles Superior Court: Systems shutdown due to ransomware
Another prominent malware in the group's arsenal is a backdoor called Dtrack (also known as Valefor and Preft), which was first used in a cyberattack targeting the Kudankulam nuclear power plant in India in 2019.

Researchers said that the Andariel – APT45 hackers are among longest-running hacking groups and their activity reflects the regime's geopolitical priorities.
“As the country relies on its cyber operations as an instrument of national power, the operations carried out by APT45 and other cyber may reflect the changing priorities of the country's leadership.“.
North Korean hackers: A major threat
North Korean hackers pose a threat to global security through a series of cyberattacks targeting critical systems and networks. These attacks can cause significant disruption and undermine trust in digital systems.
See also: Play ransomware: New Linux variant targets VMWare ESXi environments
Additionally, North Korean hackers have demonstrated their ability to infiltrate financial systems, such as banks and cryptocurrencies, causing economic instability.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, they can use their skills to steal sensitive information, such as military secrets or intellectual property, thus causing security issues and political tensions.
Source: thehackernews.com
