RULE(RULE ID:333561)

Rule General Information
Release Date: 2019-09-28
Rule Name: Andariel-2019 proto Connect to C2 Server
Rule Protection Details
Description: As a branch group of Lazarus, the North Korean APT organization, Andariel is mainly responsible for foreign military activities. Proto Module is a secret-stealing Trojan that steals various information of the victim host, including MAC address, computer name, installed software, etc.
Impact: Andariel may allow an attacker to access users' personal information such as banking information, passwords, or personal identity.
Affected OS: Windows, Linux, Others
Please contact the software vendor to update the software patch.