logo

Andariel Hackers Leveraging Remote Tools To Exploit Organizations

ID: 15d34ac1-f447-5164-9d78-12bd3de61ab9

STIX ID: report--15d34ac1-f447-5164-9d78-12bd3de61ab9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2024-03-20

Date Updated: 2026-04-22

Author: Eswar

...
...

The report details Andariel group activity against Korean companies, describing use of AndarLoader (downloader using KoiVM), ModeLoader (JS delivered via mshta), MeshAgent for remote management and lateral movement, credential theft via Mimikatz and a keylogger, and evidence removal (wevtutil). It provides MD5 hashes and C2 domains/IPs for detection and notes this as the first observed use of MeshAgent by the group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.