Summary: 2025/04/19 22:51
First reported date: 2014/07/28
Inquiry period : 2025/03/20 22:51 ~ 2025/04/19 22:51 (1 months), 1 search results
전 기간대비 신규 트렌드를 보이고 있습니다.
악성코드 유형 NetWireRC RATel SnatchCrypto Ransomware GameoverP2P 도 새롭게 확인됩니다.
공격자 Kimsuky Lazarus Silent Chollima 도 새롭게 확인됩니다.
공격기술 Campaign 도 새롭게 확인됩니다.
기관 및 기업 CrowdStrike Paloalto Japan North Korea Microsoft 도 새롭게 확인됩니다.
기타 Palo Alto 팔로알토 Victim Cryptocurrency c&c 등 신규 키워드도 확인됩니다.
aka: Andariel, GOP, Guardian of Peace, Onyx Sleet, OperationTroy, PLUTONIUM, Subgroup: Andariel, WHOis Team
Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary organization of the Lazarus threat group. WHOIS utilizes spear phishing attacks, watering hole attacks, and supply chain attacks for initial access. They have been known to exploit vulnerabilities and use malware such as Infostealer and TigerRAT. Ref.
* 최근 뉴스기사 Top3:
ㆍ 2025/03/25 Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup
Trend graph by period
Related keyword cloud
Top 100# | Trend | Count | Comparison |
---|---|---|---|
1 | NetWireRC | 1 | ▲ new |
2 | CrowdStrike | 1 | ▲ new |
3 | RATel | 1 | ▲ new |
4 | Palo Alto | 1 | ▲ new |
5 | 팔로알토 | 1 | ▲ new |
6 | Paloalto | 1 | ▲ new |
7 | SnatchCrypto | 1 | ▲ new |
8 | Ransomware | 1 | ▲ new |
9 | Japan | 1 | ▲ new |
10 | North Korea | 1 | ▲ new |
11 | Microsoft | 1 | ▲ new |
12 | Victim | 1 | ▲ new |
13 | Kimsuky | 1 | ▲ new |
14 | Cryptocurrency | 1 | ▲ new |
15 | c&c | 1 | ▲ new |
16 | IoC | 1 | ▲ new |
17 | Campaign | 1 | ▲ new |
18 | Report | 1 | ▲ new |
19 | Malware | 1 | ▲ new |
20 | UNC4736 | 1 | ▲ new |
21 | Lazarus | 1 | ▲ new |
22 | Vulnerability | 1 | ▲ new |
23 | STARDUST CHOLLIMA | 1 | ▲ new |
24 | Silent Chollima | 1 | ▲ new |
25 | GameoverP2P | 1 | ▲ new |
Special keyword group
Top 5
Malware Type
This is the type of malware that is becoming an issue.
Keyword | Average | Label |
---|---|---|
NetWireRC |
|
1 (20%) |
RATel |
|
1 (20%) |
SnatchCrypto |
|
1 (20%) |
Ransomware |
|
1 (20%) |
GameoverP2P |
|
1 (20%) |

Attacker & Actors
The status of the attacker or attack group being issued.
Keyword | Average | Label |
---|---|---|
Kimsuky |
|
1 (33.3%) |
Lazarus |
|
1 (33.3%) |
Silent Chollima |
|
1 (33.3%) |

Technique
This is an attack technique that is becoming an issue.
Keyword | Average | Label |
---|---|---|
Campaign |
|
1 (100%) |

Country & Company
This is a country or company that is an issue.
Keyword | Average | Label |
---|---|---|
CrowdStrike |
|
1 (20%) |
Paloalto |
|
1 (20%) |
Japan |
|
1 (20%) |
North Korea |
|
1 (20%) |
Microsoft |
|
1 (20%) |
Threat info
Last 5SNS
(Total : 0)No data.
News
(Total : 1)NetWireRC Attacker CrowdStrike RATel Paloalto SnatchCrypto Ransomware Japan North Korea Microsoft Victim Kimsuky Cryptocurrency c&c IoC Campaign Report Malware UNC4736 Lazarus Vulnerability STARDUST CHOLLIMA Silent Chollima GameoverP2P
No | Title | Date |
---|---|---|
1 | Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup - Malware.News | 2025.03.25 |
Additional information
No | Title | Date |
---|---|---|
1 | NDPC, Health Ministry Partner to Boost Data Protection in Healthcare - Malware.News | 2025.04.19 |
2 | Tesla to Delay Production of Cheaper EVs, Reuters Reports - Bloomberg Technology | 2025.04.19 |
3 | When Vulnerability Information Flows are Vulnerable Themselves - Malware.News | 2025.04.19 |
4 | CISA warns threat hunting staff of end to Google, Censys contracts as agency cuts set in - Malware.News | 2025.04.19 |
5 | Radiology practice reportedly working with FBI after ‘data security incident’ - Malware.News | 2025.04.19 |
View only the last 5 |
No | Title | Date |
---|---|---|
1 | Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup - Malware.News | 2025.03.25 |
2 | Tempted to Classifying APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup - Malware.News | 2025.03.25 |
3 | 韓美英 합동 사이버보안권고문 : 北 안다리엘의 해킹활동 - 이스트시큐리티 알약 블로그... | 2024.07.26 |
4 | 韓美英 합동 사이버보안권고문 : 北 안다리엘의 해킹활동 - 이스트시큐리티 알약 블로그... | 2024.07.26 |
5 | 韓美英 합동 사이버보안권고문 : 北 안다리엘의 해킹활동 - 이스트시큐리티 알약 블로그... | 2024.07.26 |
View only the last 5 |