logo

Andariel Group Exploiting Korean Asset Management Solutions (MeshAgent)

ID: 36c817ee-1eba-5c05-acf2-54051ff528eb

STIX ID: report--36c817ee-1eba-5c05-acf2-54051ff528eb

Feed Name: ASEC

Threat Score
80/100

Date Published: 2024-03-19

Date Updated: 2026-04-26

Author: Sanseo

...
...

AhnLab ASEC reports active Andariel group attacks against South Korean companies that abuse asset-management solutions to deliver loaders (AndarLoader, ModeLoader), deploy MeshAgent for remote control, and install credential-theft tools (Mimikatz) and a keylogger; the report includes behavioral details, commands observed, C2 URLs, MD5 hashes and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.