HomeSecurityNorth Korean hackers Andariel turn to ransomware

North Korean hackers Andariel turn to ransomware

North Korean hackers Andariel , who were primarily known for cyberespionage operations , have now expanded into financially motivated attacks , which include the development of ransomware .

hackers Andariel ransomware

Mandiant is tracking the group under the name APT45, although it is also known as Andariel, Nickel Hyatt, Onyx Sleet, Stonefly, and Silent Chollima.

According to researchers Taylor Long, Jeff Johnson, Alice Revelli, Fred Plan, and Michael Barnhart, APT45 has been conducting espionage since 2009 and primarily targets organizations that belong to critical infrastructure.

See also: RA World ransomware group attacks the construction sector

APT45 (like APT38-BlueNoroff, APT43-Kimsuky, and Lazarus Group), belongs to Reconnaissance General Bureau (RGB), which is the country's top military intelligence organization.

North Korean hackers Andariel – APT45 have also been linked to the development of ransomware (SHATTEREDGLASS and Maui) in attacks targeting South Korea, Japan and the US.

“It is likely that APT45 is committing cybercrime with financial motives, not only to support its own operations, but to generate funds for other North Korean state priorities,” Mandiant said.

See also: Los Angeles Superior Court: Systems shutdown due to ransomware

Another prominent malware in the group's arsenal is a backdoor called Dtrack (also known as Valefor and Preft), which was first used in a cyberattack targeting the Kudankulam nuclear power plant in India in 2019.

North Korean hackers Andariel turn to ransomware

Researchers said that the Andariel – APT45 hackers are among longest-running hacking groups and their activity reflects the regime's geopolitical priorities.

“As the country relies on its cyber operations as an instrument of national power, the operations carried out by APT45 and other cyber may reflect the changing priorities of the country's leadership.“.

North Korean hackers: A major threat

North Korean hackers pose a threat to global security through a series of cyberattacks targeting critical systems and networks. These attacks can cause significant disruption and undermine trust in digital systems.

See also: Play ransomware: New Linux variant targets VMWare ESXi environments

Additionally, North Korean hackers have demonstrated their ability to infiltrate financial systems, such as banks and cryptocurrencies, causing economic instability.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finally, they can use their skills to steal sensitive information, such as military secrets or intellectual property, thus causing security issues and political tensions.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS