North Korea-backed group accused of launching 'cyber campaign to steal military and nuclear secrets'

25 July 2024, 18:15

The group has launched cyber attacks against infrastructure across the globe.
The group has launched cyber attacks against infrastructure across the globe. Picture: Getty

By Henry Moore

Andariel began as a hacker group targeting the US and South Korea, but has since evolved to carry out specialised cyber espionage and ransomware strikes.

Listen to this article

Loading audio...

The UK's National Cyber Security Centre (NCSC) has accused the "Andariel" group of compromising organisations across the globe in a bid to obtain tightly guarded military secrets.

The NCSC, FBI and South Korea’s national intelligence service have come together to warn of the risk posed by Andariel, urging infrastructure organisations to "stay vigilant" against the cyber operations.

NCSC director of operations Paul Chichester said: “The global cyber espionage operation that we have exposed today shows the lengths that DPRK (Democratic People’s Republic of Korea) state-sponsored actors are willing to go to pursue their military and nuclear programmes.

Read more: Ex-minister Johnny Mercer will not face jail despite refusing to hand over whistleblower names to Afghan inquiry

Read more: Meta panel says deepfake policies need update amid controversy over nude images

The NCSC accuses Andariel of being part of the DPRK’s reconnaissance general bureau (RGB) 3rd bureau and believes the group poses a threat to global infrastructure.

Andariel primarily targeted military, aerospace, nuclear and engineering organisations.

Cyber attacks for increasingly common
Cyber attacks for increasingly common. Picture: Getty

The group also launched ransomware attacks against US healthcare companies in a bid to extort payments and fund their espionage, the NCSC reports.

Mr Chichester continued: “It should remind critical infrastructure operators of the importance of protecting the sensitive information and intellectual property they hold on their systems to prevent theft and misuse.

“The NCSC, alongside our US and Korean partners, strongly encourage network defenders to follow the guidance set out in this advisory to ensure they have strong protections in place to prevent this malicious activity.”

Sharing the joint advisory on X, formerly known as Twitter, the NCSC wrote: “DPRK state-sponsored threat group Andariel has been compromising organisations to steal sensitive information and IP in order to further the regime’s military and nuclear ambitions.

“These malicious operations pose a threat to critical infrastructure organisations globally. UK network defenders should follow the latest advice to help detect and mitigate this activity.”

According to the advisory, Andariel began as a hacker group targeting the US and South Korea, but has since evolved to carry out specialised cyber espionage and ransomware strikes.

More Latest News

See more More Latest News

As the couple were arrested, Marten can be heard questioning "how is that an arrest-able offence?"

‘How is that an arrestable offence?’: Constance Marten's arrogant response as police catch her after seven weeks on the run

The first glimpse of Dominic McLaughlin has been cast as Harry Potter.

Harry Potter TV series filming kicks off with first glimpse of leading star - as more cast announced

Blue Stevens, 24, died after he was attacked in Seville Street, Knightsbridge, at around 9.30pm on July 9.

Three arrested after man, 24, stabbed to death 'for his Rolex' near luxury Knightsbridge hotel

Yostin Mosquera, left, denies murdering Albert Alfonso, centre.

Man accused of suitcase murders claims he was ‘raped every day’ by one of his alleged victims

England's Shoaib Bashir celebrates after the final wicket during day five of the Third Rothesay Men's Test at Lord's, London.

England beat India by 22 runs in third Test of the series

Police personnel work at the site of an Air India plane crash in Ahmedabad, India, Friday, June 13, 2025.

Air India rules out mechanical fault on doomed flight 171 amid investigation into pilots' 'medical records'

Aristocrat Constance Marten and her partner Mark Gordon have been found guilty at the Old Bailey of the manslaughter of their newborn baby.

Crocodile tears of a killer aristocrat: Moment Constance Marten is confronted over the death of newborn baby

A man accused of trying to spy for Russia has claimed he planned to “track and expose Russian agents” to assist Israel, a court has heard.

Father-of-four accused of plotting to spy for Russia claims he planned to ‘expose Russian agents'

Pc Ellie Cook fired her Taser at Mohammed Fahir Amaaz, 20, after he and his brother, Muhammad Amaad, 26, allegedly attacked her and two Greater Manchester Police (GMP) colleagues.

‘Not an option’ to walk away from Manchester Airport suspect - police officer tells court

Police said road crime team officers initially tried to pull over the Peugeot, which was believed to be linked to drugs, on the M5.

Cocaine smuggler jailed after police find £1 million worth of drugs in car boot following 120mph chase

A sinkhole filled with water

Sinkhole opens in London borough leading to disruption from 'large amount of flooding'

Katie Wallis arrives at Cardiff Magistrates.

Former Conservative MP who harassed ex-wife handed community order

Irish Air Corps undated handout photo of Army Ranger Wing boarding the MV Matthew as part of Ireland's largest-ever drugs haul.

Irish gangsters' drugs empire laid bare after eight men jailed following Special Forces raid on 'narco-tanker'

Gregg Wallace smiling

Gregg Wallace breaks his silence saying he is "deeply sorry" for any distress caused

Four people have died following a plane crash at Southend Airport.

Plane crashed in 'fireball' at Southend Airport after dropping off patient for medical attention

Wells Town Hall and coroners court Wells Somerset England UK GB EU Europe

Former Met detective died in fire after locking himself in bedroom, inquest told