Threat actor · OAK-G09
OAK-G09 — Andariel (DPRK ransomware-and-ICS sub-cluster within the Lazarus / RGB ecosystem)
Description
OAK-G09 is the Andariel cluster: a DPRK-attributed cyber-actor cluster under the Reconnaissance General Bureau (RGB) — the same parent organisation as OAK-G01 Lazarus, OAK-G07 APT43 / Kimsuky, and OAK-G08 BlueNoroff — but operationally distinct from each of those sister clusters along three axes. (1) Primary mission: G09 runs a dual portfolio of ransomware-against-healthcare-and-critical-infrastructure operations (the Maui-ransomware family is canonical, with cryptocurrency-denominated ransom payments as the value-extraction layer) and intelligence-collection intrusions against the defence-industrial base, energy, engineering, and aerospace sectors; cryptocurrency-mining-as-monetization on compromised systems is a secondary but persistent revenue stream. The cluster's crypto angle is fundamentally the laundering tail of ransomware operations and the mining-on-compromised-infrastructure tail of espionage operations, not direct crypto-firm intrusion. (2) Targeting profile: G09 targets U.S. and ROK healthcare providers and public-health entities (the AA22-187A Maui targeting cohort), defence-industrial-base contractors, energy-sector firms, engineering-and-aerospace firms, and ICS / OT environments where intellectual-property exfiltration aligns with the DPRK weapons-and-nuclear programmes; G01 targets crypto-firm engineering staff and exchange / bridge / custody infrastructure; G08 targets crypto-firm macOS engineering pipelines specifically. (3) Dominant TTPs: G09 uses the Maui ransomware family (a manually-deployed, Korean-developed, key-management-by-operator ransomware variant explicitly distinct from the Russian-speaking RaaS ecosystem) for monetization, the DTrack RAT family for sustained intrusion, MagicRAT and YamaBot for command-and-control, and exploitation of public-facing-vulnerability classes (Log4Shell-class, MOVEit-class, ScreenConnect-class) for initial access; G01 / G08 use social-engineering-led intrusion tradecraft against crypto-firm engineering staff.
The cluster's modern public profile crystallises across three threshold events. The September 13, 2019 OFAC designation under Executive Orders 13694 / 13722 ([ofac2019dprkcyber]) was the first U.S. government action that explicitly named Andariel as a separate sanctioned entity from Lazarus and BlueNoroff, partitioning the DPRK / RGB cyber-cluster set into three named sub-units rather than treating "Lazarus" as a monolithic label. The July 6, 2022 CISA / FBI / Treasury joint advisory AA22-187A ([cisa2022aa22187a]) is the canonical operational write-up of the Maui-ransomware-against-healthcare model, including the cluster's manual-deployment-and-operator-key-management approach (Maui does not auto-generate per-victim keys; an operator interactively encrypts targeted files), the healthcare-sector targeting profile, the cryptocurrency-denominated ransom-payment workflow, and the recommendation to U.S. healthcare entities not to pay (with an explicit OFAC sanctions-violation hazard for any U.S. payer of an Andariel-attributed ransom). The July 25, 2024 DOJ indictment of Rim Jong Hyok ([doj2024rimjonghyok]), accompanied by the multi-government CISA-led joint advisory ([cisa2024andarieladvisory]), brought a named-individual-operator dimension into the cluster's confirmed-attribution surface, comparable to the Khoroshev attribution for OAK-G05 LockBit but at the state-actor end of the spectrum rather than the commercial-criminal end.
The cluster's defender-relevant signature is DPRK-state-aligned ransomware-and-ICS-intrusion with confirmed-grade public attribution, healthcare-and-DIB-vertical targeting concentration, and a cryptocurrency-payment-and-laundering tail that is structurally separable from the Lazarus / TraderTraitor crypto-firm-extraction surface. Defenders running G01-tuned controls (crypto-firm engineering social-engineering training, supply-chain build attestation, multisig-vendor diligence) will not catch G09 activity unless those controls extend to (a) healthcare-sector and DIB-sector enterprise IT estates, (b) public-facing-vulnerability rapid-patching for ICS-adjacent infrastructure, (c) ransom-payment-counterparty screening for any payment to a Maui-attributed wallet (which is structurally a sanctions-violation risk under the OFAC 2019 designation regardless of payment-cluster forensics), and (d) cryptocurrency-mining-process detection on compromised servers in DIB and engineering verticals, where xmrig-class binaries are a persistent G09 monetization signal. The G01 / G08 / G09 separation in OAK is intended to make this control split explicit: the three clusters share parent organisation and share state attribution, but the defender-control regime that protects against each is substantially different.
Targeting profile
OAK-G09's victim profile is enterprise-IT-and-ICS rather than crypto-native, but the value-extraction layer runs partly through cryptocurrency:
- U.S. and ROK healthcare providers and public-health entities — the AA22-187A canonical target class; the cluster's Maui-ransomware-against-healthcare operations specifically targeted electronic health record services, diagnostics services, imaging services, and intranet services, with the operational disruption to patient-care delivery cited by CISA as the rationale for the joint advisory.
- Defence-industrial-base (DIB) contractors — U.S. and allied DIB firms producing tanks, submarines, naval vessels, fighter aircraft, missile and radar systems, and other military hardware were named in the July 2024 DOJ indictment and the multi-government joint advisory as canonical Andariel intelligence-collection targets, with intellectual property exfiltrated to support DPRK weapons programmes.
- Energy, engineering, and aerospace firms — the broader DIB-adjacent target cohort, including engineering-services firms operating on critical-infrastructure projects; documented in the CISA 2024 joint advisory and in Symantec / Broadcom Stonefly reporting.
- ICS / OT environments — Andariel is the DPRK / RGB sub-cluster most consistently associated with ICS-adjacent targeting in the public record, distinguishing it from G01 (crypto-firm-IT-focused) and G08 (engineering-staff-focused). The cluster's ICS-targeting framing is one of the operational reasons the OFAC 2019 designation enumerated Andariel separately rather than collapsing it into a Lazarus monolith.
- Cryptocurrency-mining-on-compromised-infrastructure as opportunistic monetization — xmrig (Monero-mining) deployments on compromised DIB, engineering, and energy-sector systems are documented across multiple industry reports as a persistent secondary G09 revenue stream; mining proceeds feed into the broader DPRK financial-funding pipeline alongside Maui ransom payments.
- Cryptocurrency-industry firms as occasional rather than canonical targets — present in some industry reporting but not the dominant target class; G09 is enterprise-and-ICS-led, not crypto-native-extraction-led, and the crypto-firm targeting that does appear in G09-attributed activity is more often consistent with general intrusion-and-mining opportunism than with the engineered-extraction tradecraft that defines G01 and G08.
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; G09's intrusion surface (off-chain enterprise IT compromise via public-facing-vulnerability exploitation, supply-chain access, and operator-manual ransomware deployment) sits outside that scope and is documented under external Group ID G0138 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G09-attributable activity are concentrated on the ransom-payment-and-laundering tail and the mining-monetization tail:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader DPRK laundering chain that absorbs Maui-ransom proceeds; consistent with the sector-wide DPRK pattern documented in
[chainalysis2024dprk]and following the same post-2022 mixer-share decline trajectory as the rest of the DPRK / RGB cohort. Per-incident attribution of specific mixer-side flows to G09 (versus G01 / G08) is inferred-strong and depends on upstream-side wallet-cluster identification. - OAK-T7.002 (CEX Deposit-Address Layering) — the canonical off-ramp at the end of both the Maui-ransom-payment laundering chain and the xmrig-Monero-mining-output laundering chain (the Monero-to-fiat conversion of mining output runs through CEX deposit-address activity in the same structural way as the BTC ransom-payment tail). Per-cluster aggregate-inflow tracking against G09 watchlists is the canonical compliance-side detection on the off-ramp surface.
- OAK-T7.003 (Cross-Chain Bridge Laundering) — observed in the post-2022 DPRK / RGB laundering profile generally; per-incident G09-specific attribution is inferred-strong and relies on upstream wallet-cluster identification rather than on bridge-side fingerprints alone.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Chainalysis, TRM Labs, Mandiant, Microsoft, and Kaspersky to maintain G09-cluster identification across Maui-ransomware-version rotations, across xmrig-deployment-campaign rotations, and across the G01 / G08 / G09 sub-cluster boundary within the broader DPRK / RGB whole. As with the G01 / G07 boundary, the G01 / G08 / G09 partition is operationally meaningful but is not always cleanly resolvable per-incident from public reporting; T8.001 cluster-tracking is the canonical method for partitioning the four DPRK / RGB sub-clusters at the on-chain layer.
- Pre-incident vectors not yet in OAK v0.1 scope (TAXONOMY-GAPS):
- Public-facing-vulnerability exploitation against enterprise IT — Log4Shell-class, MOVEit-class, ScreenConnect-class, TeamCity-class, and ManageEngine-class exploitation are the dominant G09 initial-access vectors per the 2024 multi-government advisory. These are off-chain-IT-security-taxonomy behaviours that shape G09's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.
- Manual operator-deployed ransomware with operator-side key management — the Maui ransomware family is the canonical case; operator-interactive encryption with no per-victim auto-keying produces a forensic surface distinct from the Russian-speaking-RaaS ecosystem and is a G09-distinctive TTP.
- Cryptojacking via xmrig deployments on compromised infrastructure — sits between an off-chain TTP (binary-deployment-and-process-execution on a victim system) and an on-chain monetization Technique (mined-output flow into operator-controlled wallets); a future TAXONOMY-GAPS candidate for mining-on-compromised-infrastructure-as-direct-monetization parallel to the G07 mining-as-laundering-conversion gap, and the second canonical G09 monetization rail alongside the Maui ransom-payment rail.
Observed Examples
No public incidents at v0.1 — worked examples pending per-incident forensic publication.
OAK v0.1 does not currently host any per-incident worked examples under examples/ for G09-attributed activity. The crypto-on-chain surface for Andariel is the laundering tail of ransomware operations and the mining-on-compromised-infrastructure monetization tail of espionage operations, rather than direct crypto-firm intrusion of the kind documented for G01 (Ronin, Atomic Wallet, WazirX, Bybit). Per-incident Maui-ransom-payment laundering flows have not been published with the per-payment forensic granularity that supports OAK-grade worked examples; the public record sits at the cluster-level (CISA / DOJ / OFAC / industry-vendor) rather than at the per-payment-trail level. The G09 entry is therefore anchored on threshold-event public-attribution actions rather than on incident worked examples, and worked examples are flagged for v0.x once per-incident forensic publication catches up:
- OFAC 2019 DPRK cyber designations (September 13, 2019). Treasury press release SM-774 designating Lazarus, BlueNoroff, and Andariel as three separate sub-clusters subordinate to the DPRK Reconnaissance General Bureau under Executive Orders 13694 and 13722 (
[ofac2019dprkcyber]). The threshold event that established Andariel as a sanctioned entity distinct from Lazarus, and the regulatory anchor for any U.S. ransom-payment counterparty screening against G09-attributed wallets. Attribution at confirmed. - CISA / FBI / Treasury Maui-ransomware joint advisory AA22-187A (July 6, 2022). Canonical public characterisation of the Maui-ransomware-against-healthcare operational pattern, with explicit Andariel attribution, manual-operator-deployment forensics, healthcare-sector targeting profile, and an explicit OFAC sanctions-violation warning to U.S. payers of Andariel-attributed ransoms (
[cisa2022aa22187a]). Attribution at confirmed. - DOJ Rim Jong Hyok indictment (July 25, 2024). Unsealed indictment charging a named Andariel operator with a multi-year campaign of healthcare-sector ransomware attacks (Maui-family) and DIB-vertical intelligence-collection intrusions (
[doj2024rimjonghyok]); accompanied by a U.S. Department of State $10M reward for information leading to apprehension. Attribution at confirmed. - CISA-led multi-government joint advisory (July 25, 2024). Joint CISA / FBI / NSA / ROK NIS / NPA / DSA / U.K. NCSC advisory characterising Andariel as a DPRK state-sponsored cyber group conducting global espionage to advance regime military and nuclear programmes, with documented DIB / aerospace / engineering / energy targeting (
[cisa2024andarieladvisory]). Attribution at confirmed. - Cryptocurrency-mining intrusions on compromised DIB / engineering systems (2022–2026 cohort). xmrig-Monero-mining-binary deployments on compromised systems documented across multiple industry-vendor reports (Mandiant, Microsoft, Kaspersky, Symantec / Broadcom). Attribution at inferred-strong per individual deployment; the cohort-level attribution is documented at confirmed via the named industry trackers and is consistent with the DOJ-and-CISA characterisation of G09 monetization behaviour.
- Worked examples for specific G09-attributed Maui-ransom-payment laundering chains and for specific xmrig-deployment-cluster tracings are pending v0.x and will live under
examples/once per-incident forensic publication supports the OAK confirmed / inferred-strong distinction at the per-payment-trail level. Until then, defenders should treat G09 as anchored on the cluster-attribution layer and on the OFAC-sanctions-counterparty-screening surface rather than on per-incident on-chain examples.
Citations
[ofac2019dprkcyber]— U.S. Department of the Treasury press release SM-774, September 13, 2019, designating Lazarus, BlueNoroff, and Andariel under Executive Orders 13694 and 13722 as three separate DPRK / RGB cyber sub-clusters.[cisa2022aa22187a]— CISA / FBI / U.S. Treasury joint cybersecurity advisory AA22-187A, "North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector," July 6, 2022.[doj2024rimjonghyok]— U.S. Department of Justice unsealed indictment of Rim Jong Hyok, July 25, 2024, charging the named Andariel operator with healthcare-ransomware and DIB-intrusion offences; accompanied by a U.S. Department of State $10M reward.[cisa2024andarieladvisory]— CISA / FBI / NSA / ROK NIS / NPA / DSA / U.K. NCSC joint cybersecurity advisory of July 25, 2024, "North Korea state-sponsored cyber group conducts global espionage campaign to advance regime's military and nuclear programs."[mandiantapt452024]— Mandiant APT45 report, July 25, 2024, characterising the cluster's TTPs across financially-motivated operations and weapons-programme-aligned espionage; tracks substantially the same operator set as KISA / CISA Andariel attribution.[microsoftonyxsleet2024]— Microsoft Threat Intelligence reporting on Onyx Sleet (formerly Plutonium) characterising the cluster's tooling, public-facing-vulnerability exploitation pattern, and DIB-vertical targeting.[symantecstonefly2024]— Symantec / Broadcom reporting on Stonefly (partial-overlap industry name for the Andariel intrusion sub-stream against U.S. organisations); 2024 reporting documenting continued post-Rim-Jong-Hyok-indictment activity.[chainalysis2024dprk]— DPRK-attributed crypto-theft scale companion citation (cited from G01, G04, and G07 as well); aggregate DPRK volumes that the G01 / G04 / G07 / G08 / G09 partition jointly explains.
Discussion
On the attribution-strength split. The cluster-and-state-attribution layer (Andariel = DPRK RGB) is confirmed — U.S. Treasury OFAC SM-774 (September 2019), CISA / FBI / Treasury AA22-187A (July 2022), DOJ Rim Jong Hyok indictment (July 2024), CISA-led multi-government joint advisory (July 2024), ROK NPA / NIS attributions, and a multi-vendor industry-forensic record converge. The per-incident sub-cluster partition between G01 (Lazarus / TraderTraitor), G08 (BlueNoroff / APT38), and G09 (Andariel) within the broader DPRK / RGB whole is operationally meaningful but is inferred-strong in many cases rather than confirmed; the public record does not always cleanly resolve which RGB sub-element ran a given on-chain laundering or mining-monetization sequence. OAK contributors writing G09-attributed examples should preserve this split per-incident, with the same convention used for G07: attributing an action to "DPRK / RGB" is confirmed-grade; attributing it specifically to G09 requires explicit named-vendor (Mandiant APT45, Microsoft Onyx Sleet, Symantec Stonefly, Kaspersky Andariel, CISA / FBI / DOJ / OFAC) attribution or technical-fingerprint-led sub-cluster identification.
On why OAK-G09 is Andariel rather than a sub-section of G01. Treating "DPRK = Lazarus" was the dominant pre-2019 industry framing, and the September 2019 OFAC designation was the U.S. government action that explicitly broke that monolith into three separately-sanctioned entities (Lazarus, BlueNoroff, Andariel). The three sub-clusters share parent organisation (RGB), share state attribution, and intersect in the broader DPRK-attributed-financial-cyber volume aggregates, but they have distinct operational ownership, distinct primary missions (regime-revenue crypto theft for G01; macOS-engineering crypto-firm intrusion for G08; ransomware-and-ICS-and-mining for G09), distinct TTPs, distinct targeting profiles, and distinct downstream monetization signatures. Naming G09 as a separate Group reflects the post-2019 sanctions-architecture reality and avoids the DPRK-monolith fallacy on the same per-cluster-identity principle that motivated splitting G07 from G01 and G08 from G01.
On the G01 / G08 / G09 cluster-boundary section. The three DPRK / RGB cyber-cluster entries in OAK partition the public-record cluster space along three operator-behaviour axes:
- G01 (Lazarus / TraderTraitor) — primary mission regime-revenue crypto theft; targets crypto-firm engineering staff and exchange / bridge / custody infrastructure; dominant TTP supply-chain compromise of vendor developer workstations and validator-key extraction (Ronin, Harmony, Atomic Wallet, WazirX, Bybit); laundering rail bespoke operator-controlled wallet-cluster routing through mixers and cross-chain bridges; per-incident value extraction in the $10M–$1.5B range; large-N high-value extraction surface.
- G08 (BlueNoroff / APT38) — primary mission regime-revenue crypto-firm intrusion via macOS-engineering-pipeline compromise; targets macOS-developer workstations at crypto-firm engineering teams and at the broader Web3 ecosystem; dominant TTP social-engineering-led delivery of macOS payloads (RustBucket, KandyKorn, ObjCShellz family) under fabricated venture-capital-or-investor personas; laundering rail substantially overlaps with the broader G01 surface; targeting profile is the macOS-engineering subset of the G01 / TraderTraitor whole and is operationally separable from the supply-chain-vendor and validator-key surfaces.
- G09 (Andariel) — primary mission ransomware-against-healthcare-and-critical-infrastructure plus DIB / energy / engineering / aerospace intelligence collection plus mining-on-compromised-infrastructure monetization; targets enterprise-IT and ICS / OT environments rather than crypto-native firms; dominant TTPs Maui-family operator-manual ransomware deployment and DTrack / MagicRAT / YamaBot intrusion tooling and xmrig-Monero-mining deployment; monetization model is ransom payments plus mining output rather than direct on-chain extraction; per-incident value extraction in the much-smaller Maui-ransom range (typically six- to seven-figure ransom demands, far below the G01 / G08 per-incident scale).
The three clusters are sister sub-units under shared state direction, not the same operator. Defenders running G01-tuned crypto-firm controls leave the G09 surface entirely uncovered (healthcare, DIB, ICS, and engineering verticals are outside the crypto-firm control regime); defenders running G09-tuned enterprise-IT-and-ICS controls leave the G01 / G08 surface uncovered (crypto-firm engineering tradecraft is outside the enterprise-IT-and-ICS control regime). The G01 / G08 / G09 separation in OAK is intended to make this control-regime split explicit, parallel to the G01 / G07 separation that makes the regime-revenue / espionage-self-funding split explicit and the G01 / G04 separation that makes the engineering-pipeline / hiring-pipeline split explicit.
On the Andariel × Black Basta overlap. Industry reporting from 2022 onwards has flagged tooling and TTP overlaps between Andariel and the Black Basta ransomware-as-a-service operation — including overlaps in initial-access tradecraft, in some delivery binaries, and in lateral-movement patterns. The strongest public framing of this overlap treats it as an operational-supplier-or-affiliate-borrowing relationship rather than as a shared-cluster-identity claim: Andariel may have leveraged Black Basta–developed tooling or affiliate-network access for specific intrusions, but Black Basta as a whole is documented as a Russian-speaking commercial RaaS operation operationally distinct from a DPRK / RGB sub-cluster. OAK does not publish the Andariel × Black Basta overlap as confirmed at v0.1; the overlap is inferred-strong at best, and contributors writing G09-attributed examples should not collapse the two operator surfaces. Any G09 example invoking Black Basta tooling should explicitly flag the inference and cite the relevant industry write-up rather than treating the connection as a settled attribution.
On the relationship to OAK-G05 (LockBit) and OAK-G06 (Evil Corp). G09 (Andariel ransomware) and G05 (LockBit RaaS) and G06 (Evil Corp) all run cryptocurrency-denominated extortion as the value-extraction layer, but they sit on different sides of the state-aligned-vs-commercial-criminal axis. G09 is state-directed under DPRK / RGB substrate with manually-deployed Maui-family ransomware and operator-side key management; G05 is commercial-criminal under Russian-resident operating substrate with a RaaS affiliate model and automated-encryptor distribution; G06 is commercial-criminal with documented Russian state-intelligence operational entanglement. The three clusters do not share infrastructure, do not collaborate operationally on the public record, and should not be co-clustered in defender models. The structural similarity is in the ransom-payment-counterparty-screening control surface rather than in the operator identity itself — defenders running ransom-payment screens against any of G05 / G06 / G09 operate against confirmed-grade OFAC-designated cluster watchlists, and the screening-side methodology is shared even when the upstream-extraction operators are not.
On the relationship to OAK-G03 (Russian laundering infrastructure). Unlike G05 and G06, G09 does not show a documented dependency on G03 (Garantex / Grinex / A7A5) downstream laundering venues at the operator-personal level; the DPRK / RGB cluster set generally launders through bespoke operator-controlled chains rather than through Russian-resident commercial laundering venues. Defenders running joint G03-and-G09 watchlists should not expect substantial overlap on the per-incident inflow surface, in contrast to the substantial G03-and-G05 overlap and G03-and-G06 overlap documented elsewhere in OAK.
On TAXONOMY-GAPS. OAK v0.1 does not yet have a Tactic for cryptojacking-on-compromised-infrastructure-as-direct-monetization (the xmrig-on-DIB-systems pattern is the canonical G09 case), nor for operator-manually-deployed-ransomware-with-operator-side-key-management (the Maui pattern is the canonical G09 case). Both are G09-distinctive and are tracked here under "pre-incident vectors not yet in OAK v0.1 scope." A v0.x OAK update may introduce dedicated Tactics for both patterns; G09 will then anchor the worked examples.
On v0.x evolution. G09's 2026+ trajectory will depend on (a) whether the Maui-ransomware family continues as a dedicated G09 monetization rail or is supplemented / replaced by other operator-deployed ransomware codebases (the Black Basta-overlap question is one signal here, alongside any future named DPRK ransomware codebase); (b) whether further OFAC, DOJ, and allied designations and indictments sustain the post-2024 enforcement tempo (the Rim Jong Hyok indictment-plus-State-Department-reward architecture sets a Khoroshev-class precedent at the state-actor end of the spectrum); (c) whether per-incident attribution between G01, G08, and G09 becomes more cleanly resolvable as forensic providers refine sub-cluster fingerprints; (d) whether the cryptojacking-as-monetization rail expands or contracts as a fraction of G09's revenue mix; and (e) whether ICS / OT targeting by G09 produces a documented direct-disruption incident on the public record (as opposed to the intelligence-collection-only profile that has dominated the public record to date). OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the DPRK / RGB cohort — additional named RGB or non-RGB cyber sub-elements, named successor or splinter clusters from any of G01 / G07 / G08 / G09 — would each warrant their own OAK-Gnn entry rather than extension of an existing G entry, on the same per-cluster identity principle that motivated splitting G07, G08, and G09 from G01 in the first place.