---
title: "North Korea-backed cyber group prying into critical US infrastructure! | DuoCircle"
description: "North Korea-backed cyber group prying into critical US infrastructure!"
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/"
---

Quick Answer

A North Korea-backed cyber-espionage group, tracked as Andariel by US agencies, APT45 by Google Mandiant, and Onyx Sleet by Microsoft, is targeting US aerospace, defense, engineering, nuclear, and healthcare organizations to feed Pyongyang's military and nuclear programs and fund operations through ransomware. The group also targets Japan, India, and South Korea. Stolen material includes data on combat ships, self-propelled howitzers, tanks, autonomous underwater vehicles, missiles, fighter aircraft, radars, missile defense systems, nano-satellites, uranium processing and storage, robotics, shipbuilding, and 3D printing. The US has indicted Rim Jong Hyok over attacks on US Air Force bases and NASA, with a $10 million reward for information. CISA, FBI, and NSA have published a joint advisory noting Andariel has shifted from spear-phishing to vulnerability exploitation, then uses custom tools and malware for remote access, lateral movement, and exfiltration. Mandiant assesses the group active since 2009; Microsoft tracks it from 2014\. Recommended defenses: harden email authentication, protect against web shells, and lock down remote access.

North Korea-backed cyber group prying into critical US infrastructure!

Your browser does not support the audio element.

[ Download episode](https://media.mailhop.org/duocircle/images/2024/08/North-Korea-backed-cyber-group-prying-into-critical-US-infrastructure.mp3) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=North%20Korea-backed%20cyber%20group%20prying%20into%20critical%20US%20infrastructure!&url=undefined%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F&title=North%20Korea-backed%20cyber%20group%20prying%20into%20critical%20US%20infrastructure! "Share on Reddit") [ ](mailto:?subject=North%20Korea-backed%20cyber%20group%20prying%20into%20critical%20US%20infrastructure!&body=Check out this article: undefined%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2024/08/what-is-dkim.jpg) 

A [cyber-espionage group](https://thehackernews.com/2024/07/cyber-espionage-group-xdspy-targets.html) backed by North Korea has been sneaking into the vital intellectual property and **technical information of the US**. The group is a part of North Korea’s foreign intelligence service. _From aerospace to defense, engineering companies to nuclear science, the group has been prying into_ _[critical infrastructures](https://www.waterisac.org/portal/ransomware-resilience-%E2%80%93-sophos-report-analyzes-ransomware-critical-infrastructure)._ Their core purpose is to **amplify their North Korean military** and nuclear programs. As per the US government, the group targets [US healthcare centers](https://www.govtech.com/security/significant-cyber-attack-impacts-health-care-system-nationwide) and leverages [ransomware](/resources/locky-ransomware) to financially compensate the campaign.

The CISA (US Cybersecurity and Infrastructure Security Agency), the FBI, and the NSA (National Security Agency) are working together to combat this situation. As per their information, the [North Korea-backed group](https://cxotoday.com/press-release/cyfirma-classifies-notorious-lazarus-group-north-korea-backed-hacker-group-behind-indian-crypto-exchange-wazirx-breach/) is targeting the USA as well as other countries such as **Japan, India, and South Korea**.

The key player in this malicious campaign is Rim Jong Hyok. The US government has announced a [$10 million reward](https://www.spiceworks.com/it-security/cyber-risk-management/news/us-government-indicts-north-korean-hacker-rim-jong-hyok-offers-reward/) to anyone who can bring valid information regarding **Rim Jong Hyok’s arrest**. Rim Jong Hyok is indicted with charges of [cyberattacks on US air force bases and NASA](https://san.com/cc/n-korea-hackers-steal-military-secrets-hit-air-force-bases-nasa-us-says/).

[![cyberattack](https://media.mailhop.org/duocircle/images/2024/08/SMTP-relay-1356.jpg)](https://media.mailhop.org/duocircle/images/2024/08/SMTP-relay-1356.jpg)

The [North Korean cyber campaign](https://therecord.media/north-korea-andariel-apt45-weapons-systems-nuclear-facilities) that goes by the name Andariel is eyeing broad and varied information this time. They have been accessing information related to **defense departments** such as combat ships, self-propelled howitzers, heavy and light tanks, autonomous underwater vehicles, and so on. 

From aerospace companies, [Andariel is stealing information](https://breakingdefense.com/2024/07/us-south-korean-warn-north-korean-hacking-group-andariel-targets-defense-aerospace-firms/) pertaining to missiles, fighter aircraft, radars, **missile defense systems**, nano-satellite, and so on. They are also prying into the [nuclear sector](https://www.bbc.com/news/articles/cjl6p3wj52no) for vital information related to material waste, **uranium processing**, storage, etc. Lastly, from engineering firms, the North Korean cyber group is [stealing information](https://interestingengineering.com/military/south-korea-north-korea-hacking-microchip) such as robotics, shipbuilding, 3D printing, additive printing, etc.

Proper [cybersecurity](/) measures are being taken, such as **strengthening** [email authentication](/resources/email-authentication), protection against [web shells](https://en.wikipedia.org/wiki/Web%5Fshell), and [remote access protection](https://www.cloudflare.com/learning/access-management/what-is-remote-access-security/). 

[![phishing protection](https://media.mailhop.org/duocircle/images/2024/08/dmarc-generator.jpg)](https://media.mailhop.org/duocircle/images/2024/08/dmarc-generator.jpg)

From Google’s [Mandiant](https://www.mandiant.com/) to [Microsoft](https://www.microsoft.com/en-us/), **everyone is tracking Andariel**. The former believes that the cyber group has been active since 2009\. As per the Microsoft team, Andariel has been active since 2014\. 

Google Mandiant tracks Andariel as **APT45** and has [emphasized](https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine) the group’s increasing [ransomware attacks](/data-privacy/8-most-nefarious-ransomware-attacks-from-2017-to-mid-2023/) in recent times. Microsoft tracks Andariel as **Onyx Sleet** and has recently shared an [update](https://www.microsoft.com/en-us/security/blog/2024/07/25/onyx-sleet-uses-array-of-malware-to-gather-intelligence-for-north-korea/) which focuses on the threat actor’s shift from [spear-phishing](/content/phishing-prevention/spear-phishing-examples) to leveraging [vulnerability exploits](https://industrialcyber.co/cisa/north-korean-hackers-exploiting-weak-dmarc-security-policies-to-mask-spearphishing-efforts/) in order to gain illegitimate access to critical information of national importance.

_As per the [US government advisory](https://media.defense.gov/2024/Jul/25/2003510137/-1/-1/0/Joint-CSA-North-Korea-Cyber-Espionage-Advance-Military-Nuclear-Programs.PDF)\_\_, Andariel is **actively exploiting** vulnerabilities to break into US defense and other critical sectors_. As soon as they access a specific network, Andariel threat actors utilize different types of custom tools as well as [malware](https://thehackernews.com/2024/07/north-korea-linked-malware-targets.html) in order to gain remote access, facilitate lateral movement, and eventually steal vital data. The advisory also mentions other tactics and strategies deployed by Andariel in detail. The core idea of releasing the advisory is to enable relevant authorities to **take significant precautionary measures** and [protect critical information](/content/email-phishing-protection/best-phishing-protection). The detailed advisory also contains signs that organizations can look up to in order to ensure that the [threat actor](https://www.securityweek.com/new-north-korean-threat-actor-engaging-in-espionage-revenue-generation-attacks/) is actually lurking on their systems and networks.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F) [ ](https://twitter.com/intent/tweet?text=North%20Korea-backed%20cyber%20group%20prying%20into%20critical%20US%20infrastructure!&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Fnorth-korea-backed-cyber-group-prying-into-critical-us-infrastructure%2F) Copy 

Related Articles

- [ ![Email Threats](https://media.mailhop.org/duocircle/images/2023/07/hosted-email-server-3175.jpg)  Are MortalKombat Ransomware and Tengyun Snake Attacks Emerging Email Threats? Blog ](/blog/data-privacy/are-mortalkombat-ransomware-and-tengyun-snake-attacks-emerging-email-threats/)
- [ ![Hacker Taunts](https://media.mailhop.org/duocircle/images/2022/09/spf-record-tester-7545.jpg)  Hacker Taunts TikTok After Stealing Over 2 Billion Records in a Massive Data Breach Blog ](/blog/data-privacy/hacker-taunts-tiktok-after-stealing-over-2-billion-records-in-a-massive-data-breach/)
- [ ![IntelBroker Threat Actors](https://media.mailhop.org/duocircle/images/2023/02/spf-record-generator-7980.jpg)  IntelBroker Threat Actors Steal Sensitive Data of 11 Million Weee Customers Blog ](/blog/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/)
- [ ![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2023/05/SPF-record-checker-7009.jpg)  Malicious Actors Use Azure Serial Console to Gain Unauthorized Access to Microsoft VMs Blog ](/blog/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/)

## Related Articles

[  Privacy 5m  Are MortalKombat Ransomware and Tengyun Snake Attacks Emerging Email Threats?  Jul 20, 2023 ](/blog/data-privacy/are-mortalkombat-ransomware-and-tengyun-snake-attacks-emerging-email-threats/)[  Privacy 6m  Hacker Taunts TikTok After Stealing Over 2 Billion Records in a Massive Data Breach  Sep 19, 2022 ](/blog/data-privacy/hacker-taunts-tiktok-after-stealing-over-2-billion-records-in-a-massive-data-breach/)[  Privacy 7m  IntelBroker Threat Actors Steal Sensitive Data of 11 Million Weee Customers  Feb 20, 2023 ](/blog/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/)[  Privacy 4m  Malicious Actors Use Azure Serial Console to Gain Unauthorized Access to Microsoft VMs  May 25, 2023 ](/blog/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"North Korea-backed cyber group prying into critical US infrastructure!","description":"North Korea-backed cyber group prying into critical US infrastructure!","url":"https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/","datePublished":"2024-08-05T11:12:20.000Z","dateModified":"2025-08-22T11:34:16.000Z","dateCreated":"2024-08-05T11:12:20.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/"},"articleSection":"data-privacy","keywords":"News, Security, Updates","wordCount":514,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/what-is-dkim.jpg","caption":"cybersecurity","width":900,"height":512},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Privacy"},{"@type":"ListItem","position":3,"name":"North Korea-backed cyber group prying into critical US infrastructure!","item":"https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Privacy","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"North Korea-backed cyber group prying into critical US infrastructure!","item":"https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"North Korea-backed cyber group prying into critical US infrastructure!","description":"North Korea-backed cyber group prying into critical US infrastructure!","url":"https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/","datePublished":"2024-08-05T11:12:20.000Z","dateModified":"2025-08-22T11:34:16.000Z","dateCreated":"2024-08-05T11:12:20.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/data-privacy/north-korea-backed-cyber-group-prying-into-critical-us-infrastructure/"},"articleSection":"data-privacy","keywords":"News, Security, Updates","wordCount":514,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/08/what-is-dkim.jpg","caption":"cybersecurity","width":900,"height":512},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
