Silent Chollima is a Lazarus subgroup targeting South Korean organizations.
Analyst brief
Silent Chollima (aka Andariel, Onyx Sleet), assessed to be a subgroup of the Lazarus threat group, primarily targets South Korean corporations and institutions. Their initial access TTPs heavily rely on spearphishing attachments, drive-by compromises (watering hole), and supply chain attacks. They leverage stealth techniques like steganography, conduct network and process discovery, and deploy malware such as Rifdoor and gh0st RAT for C2 communication. Defenders should prioritize email gateway hardening, timely patching of browser and client-side vulnerabilities, and enhanced monitoring for unusual discovery activities and encrypted C2 traffic.
Silent Chollima
OperationTroyGuardian of PeaceGOP
unknown
Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary organization of the Lazarus threat group. WHOIS utilizes spear phishing attacks, watering hole attacks, and supply chain attacks for initial access. They have been known to exploit vulnerabilities and use malware such as Infostealer and TigerRAT.