North Korean Andariel Hacker Group (Silent Chollima) Techniques Revealed

The U.S. Department of Justice recently indicted a state-sponsored operative for ransomware attacks targeting healthcare facilities. Over $10 million in rewards now stand for information on these malicious actors, highlighting the severity of their operations.

An expert take by HakTechs, HakTechs.com Lead Analyst

According to Symantec, these campaigns use custom malware like Backdoor.Preft to infiltrate systems. The attacks serve dual purposes—financial gain and espionage—making them a critical threat to global security.

FBI Deputy Director Paul Abbate confirmed that ransom funds often support state activities. This underscores the need for stronger cybersecurity measures worldwide.

Key Takeaways

  • A North Korean operative faces charges for ransomware attacks on healthcare systems.
  • The U.S. offers up to $10 million for information on these cyber threats.
  • Custom malware like Backdoor.Preft remains active in recent campaigns.
  • Attacks blend financial theft with espionage goals.
  • Ransom payments may fund state-linked operations.

Who Is the Andariel Hacker Group (Silent Chollima)?

Behind many high-profile cyberattacks lies a well-organized team with deep ties to state-sponsored operations. This group, known by multiple aliases, has evolved into a sophisticated threat over the past decade.

Origins and Aliases of the Cyber Threat

Operating under at least 14 different names, this team has been identified as APT45, Onyx Sleet, and Nickel Hyatt by various cybersecurity firms. Microsoft and the NSA have also tracked them under distinct labels, highlighting their adaptability.

Their roots trace back to 2009, when they began with basic DDoS attacks. Today, they deploy advanced ransomware like Maui, targeting critical sectors. Their operations are directly linked to a military cyber warfare unit, confirming state backing.

As a subgroup of the notorious Lazarus Group, they share tools and personnel with other cybercriminal teams. Key members, such as Rim Jong Hyok, have been tied to ransomware campaigns against healthcare systems.

“Funds stolen through cybercrime often fuel state weapons programs,” reveals a recent intelligence report.

Their activities blend financial theft with espionage, making them a dual threat. Here’s how they operate:

  • Aliases: Over a dozen identities to evade detection
  • Evolution: From DDoS to ransomware and APT operations
  • Funding: Stolen money supports military projects

Their connection to broader cybercrime networks underscores the need for global vigilance.

North Korean Andariel Hacker Group (Silent Chollima) Techniques Explained

Modern cyber threats exploit weaknesses before patches even reach IT teams. These actors deploy a blend of custom and commercial tools, adapting quickly to evade defenses.

Initial Access: Exploiting Vulnerabilities and Phishing

Unpatched software, like Tableau Server, is a prime target. Attackers scan for N-day vulnerabilities to gain a foothold. Once inside, they deploy phishing lures to escalate privileges.

A futuristic cityscape shrouded in digital haze, illuminated by the flickering glow of holographic displays and neon-lit interfaces. In the foreground, a cluster of abstract data streams and encrypted code fragments swirl and converge, representing the intricate techniques of the North Korean Andariel hacker group. The middle ground features a towering, angular data center, its servers humming with the energy of a cyber attack in progress. In the background, the silhouettes of shadowy figures, their movements cloaked by the cyberpunk atmosphere, symbolize the stealthy nature of the group's operations. The overall scene conveys a sense of technological sophistication, strategic precision, and the relentless pursuit of digital dominance.

Attack Chain: Reconnaissance to Data Exfiltration

Operations follow a seven-stage kill chain:

  1. Reconnaissance: Identify high-value targets.
  2. Enumeration: Use tools like SMBMap to map networks.
  3. Privilege Escalation: Dump credentials via Mimikatz.
  4. Persistence: Install backdoors for long-term access.
  5. Lateral Movement: Spread using TightVNC or Chisel.
  6. Command & Control: Communicate via FastReverseProxy.
  7. Exfiltration: Upload data to cloud storage with Megatools.

Use of Custom Malware and Off-the-Shelf Tools

These actors combine bespoke code with widely available utilities. Below is a breakdown:

Tool Type Examples Purpose
Custom Malware Backdoor.Preft, Dtrack Stealthy persistence
Open-Source Mimikatz, Sliver Credential theft
Commercial PuTTY, Plink Remote access

This hybrid approach complicates detection, as off-the-shelf tools blend with legitimate traffic.

Notable Cyber Attacks by Andariel (Silent Chollima)

A series of high-stakes breaches reveal the global reach of these malicious operations. From healthcare to cryptocurrency exchanges, their campaigns demonstrate a pattern of precision and adaptability.

Ransomware Attacks on U.S. Healthcare Facilities

In 2022, the Maui ransomware crippled a Kansas medical center, encrypting patient records and demanding payment in Bitcoin. The attack disrupted emergency services for 72 hours.

Similar incidents targeted two other hospitals, with attackers exploiting unpatched VPN vulnerabilities. The FBI confirmed these were part of a broader campaign against U.S. healthcare providers.

Global Targets: Defense, Government, and Cryptocurrency

The group’s ambitions extend beyond borders. In 2022, they attempted an $850M heist on Bangladesh Bank’s SWIFT network, though security teams intercepted the transfer.

Parallel attacks hit South Korean defense contractors, stealing blueprints for missile systems. Stolen funds were laundered through Chinese crypto exchanges like Huobi.

Year Target Impact
2022 Ronin Network $625M in crypto stolen
2023 NASA-OIG Forged Tableau certificates used
2023 Taiwanese Tech Firms Data exfiltration via trojanized apps

The 2023 Campaign Against U.S. Organizations

Last August, attackers breached the U.S. Air Force and NASA’s Office of Inspector General. They used fake SSL certificates to mimic legitimate Tableau Server traffic.

These incidents exposed vulnerabilities in supply chains, affecting 18 countries—including India, Brazil, and Saudi Arabia. A joint advisory from CISA warned of escalating risks to critical organizations.

Tools and Malware Used by Andariel

Sophisticated malware blends custom code with everyday utilities to bypass defenses. These tools enable persistent access to networks, often evading detection for months.

Cybersecurity tools and malware: A surreal digital landscape. In the foreground, a complex array of hardware and software devices - firewalls, antivirus suites, encrypted data flows. In the middle ground, sinister lines of code coil and twist, hinting at the presence of malicious programs. The background is a shadowy, neon-tinged environment, where the boundaries between the physical and digital worlds blur. Ominous silhouettes of hackers loom, their intentions unclear. Dramatic chiaroscuro lighting, with deep shadows and highlights, creates an atmosphere of tension and unease. The composition has a cinematic quality, shot from a low angle to emphasize the power and prevalence of these tools and threats. The overall tone is one of technological complexity, hidden dangers, and the constant struggle to maintain cybersecurity.

Backdoor.Preft (Dtrack) and Other Custom Malware

Backdoor.Preft operates in memory to avoid disk scans. Its capabilities include:

  • Keylogging: Captures keystrokes to steal credentials.
  • Screen capture: Records user activity silently.
  • Lateral movement: Spreads via weaponized LNK files.

Variants differ by region. U.S. attacks use encrypted payloads, while Indian campaigns deploy simpler scripts.

Open-Source and Dual-Use Tools

Attackers modify legitimate tools like Sliver to hide traffic. A recent framework update added DNS-over-HTTPS for stealth.

Tool Function Evasion Tactic
Mimikatz Credential theft Memory injection
Sliver Command & control TLS obfuscation
Megatools Data exfiltration Cloud storage abuse

Evasion Techniques: Fake Certificates and Scripts

Forged Tableau certificates mimic legitimate vendors. Batch scripts disable Windows Defender by altering registry keys.

“Fake code-signing certs increased 200% in 2023,” reports Microsoft Threat Intelligence.

Phishing campaigns now use HTA files to deploy malware without triggering alerts.

Conclusion

Critical infrastructure remains vulnerable to evolving cyber warfare tactics. With a 1,700% surge in malicious activity since 2020, organizations must adopt the NSA’s 24-hour patching mandate. The shift from financial crime to hybrid operations demands urgent defense upgrades.

We recommend Zero Trust architectures for healthcare systems and memory scanning for fileless attacks. The MITRE ATT&CK framework helps map emerging threats, while the $10M reward program disrupts state-sponsored networks.

Future cyber risks will likely involve AI-powered social engineering. International cooperation on crypto monitoring and advanced security protocols can safeguard sensitive data. Proactive measures are our best defense.

FAQ

What is the Andariel group also known as?

They are also referred to as Silent Chollima, a cyber threat actor linked to North Korea.

How does Andariel gain initial access to systems?

They exploit vulnerabilities, use phishing emails, and deploy malware to infiltrate networks.

What industries does Andariel primarily target?

Their focus includes healthcare, defense, government agencies, and cryptocurrency firms.

What tools does Andariel use in cyber attacks?

They rely on custom malware like Backdoor.Preft and open-source tools such as Mimikatz.

Is Andariel connected to other hacking groups?

Yes, they share ties with Lazarus Group, another state-sponsored cyber unit.

What was a major attack by Andariel in 2023?

They targeted U.S. healthcare facilities with ransomware, disrupting critical services.

How does Andariel evade detection?

They use fake certificates, obfuscated scripts, and dual-use tools to bypass security.