AndarLoader
AndarLoader is a custom malware implant/RAT associated with the DPRK Reconnaissance General Bureau (RGB) 3rd Bureau threat group Andariel, also tracked as Onyx Sleet and formerly as PLUTONIUM, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa. It is listed in a July 2024 joint FBI-led Cybersecurity Advisory as one of multiple Andariel-developed RATs and implants used in the group’s cyber espionage and ransomware operations. The advisory attributes Andariel’s activity to campaigns targeting defense, aerospace, nuclear, and engineering organizations for sensitive military information and intellectual property, with additional targeting of medical and energy sectors; the group has also funded espionage through ransomware operations against U.S. healthcare entities.
Within the advisory, AndarLoader is identified as part of a broader Andariel malware ecosystem used after initial compromise. The actors commonly obtain access by exploiting public-facing web servers and known vulnerabilities, including CVE-2021-44228 (Log4Shell), then deploy web shells, establish persistence via Scheduled Tasks, steal credentials using tools such as Mimikatz, move laterally with SMB and RDP, and exfiltrate data via cloud services or tools such as PuTTY and WinSCP. The advisory states Andariel-developed implants and RATs, including AndarLoader, support capabilities such as arbitrary command execution, keylogging, screenshots, file and directory listing, browser history retrieval, process snooping, and uploading content to command-and-control infrastructure. The actors also use tunneling and proxy tools, disguise command and control within HTTP traffic, and routinely pack late-stage tooling with VMProtect and Themida for evasion.
The provided content does not include AndarLoader-specific indicators of compromise distinct from the broader Andariel advisory, but it does state that the advisory contains hashes, user-agent strings, and YARA rules covering the group’s activity and tooling.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over the last 15 years, the group has developed RATs, including the following... ▪ AndarLoader
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Resource Development
1 techniqueThese tools include functionality for executing arbitrary commands... and uploading content to command and control (C2) [T1587.001, T1587.004].
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.