Apt45

Threat Actor updated a month ago (2024-10-17T13:03:35.958Z)
Download STIX
Preview STIX
APT45, also known as Andariel, Onyx Sleet, and Silent Chollima, is a North Korean threat actor associated with the Reconnaissance General Bureau, a military intelligence agency. This group has been operational since at least 2009, making it one of North Korea's longest-running cyber operators. Their activities reflect North Korea's geopolitical priorities, initially focusing on cyber espionage against government and defense entities but have expanded to include targets in healthcare and crop science sectors. The group's operations have evolved over time, shifting from traditional cyber espionage to more financially motivated attacks such as ransomware. The group has been implicated in a series of global cyberattacks, using laundered ransom payments to purchase internet infrastructure for hacking purposes. These funds were reportedly funneled through China-based facilitators. According to court documents, Rim and his co-conspirators within APT45 used this infrastructure to exfiltrate sensitive defense and technology information from entities across the globe. Despite these activities being known to authorities, the group continues its operations. Recently, the U.S. Department of Justice indicted members of APT45, also known as the Stonefly group, for their ongoing financially motivated cyberattacks against U.S. organizations. However, despite this legal action, researchers at Google's Mandiant have observed that the group continues its activities unabated. Mandiant reports indicate an increase in financially motivated attacks, including ransomware, even as the group maintains its cyber espionage mission.
Description last updated: 2024-10-17T12:34:56.629Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Stonefly is a possible alias for Apt45. Stonefly, also known as Andariel, Silent Chollima, Onyx Sleet, and APT45, is a threat actor group that has been active since at least 2015 and is believed to be linked to the North Korean government. The group has been involved in various attacks, including ransomware campaigns against Healthcare an
2
Silent Chollima is a possible alias for Apt45. Silent Chollima, also known as Stonefly or APT45, is a threat actor with links to North Korea's foreign intelligence agency, the 3rd Bureau of the Foreign Intelligence and Reconnaissance General Bureau. The group has been active since at least 2015, when it began shifting its objectives. Silent Chol
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Apt45 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more